stack-ai

Warn

Audited by Socket on Apr 30, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s capabilities generally match its stated purpose, and the CLI comes from an official npm package with documentation support. However, all Stack AI auth and action traffic is mediated through Membrane rather than direct Stack AI APIs, creating meaningful third-party credential and data-flow risk; combined with unpinned `@latest` installs, this makes the skill medium risk rather than benign.

Confidence: 84%Severity: 56%
Audit Metadata
Analyzed At
Apr 30, 2026, 03:23 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fstack-ai%2F@770a749f2a13720d90052dca813c1a5c5e1b763d
Security Audit — socket — stack-ai