stability-ai

Warn

Audited by Socket on Sep 22, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's purpose is plausible, but its actual footprint is misaligned because it installs a third-party CLI and routes authentication and API traffic through Membrane rather than using Stability AI's direct official API flow. This is not confirmed malware, but it creates meaningful credential-forwarding and intermediary data-flow risk.

Confidence: 90%Severity: 76%
Audit Metadata
Analyzed At
Sep 22, 2026, 03:14 AM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fstability-ai%2F@c927643464f21a9ffb75d2ca78c724526f19eb93ee32f3f027c36e4a710e0d26
Security Audit — socket — stability-ai