stannp

Warn

Audited by Socket on May 1, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is broadly consistent with a Membrane-hosted Stannp integration and uses an official same-org npm CLI, so there is no strong evidence of malware. However, it shifts trust and data flow from direct Stannp APIs to Membrane-managed services, and the install/execution path is unpinned (`@latest`, `npx`). That makes this a medium-risk third-party gateway skill rather than a simple direct Stannp integration.

Confidence: 88%Severity: 56%
Audit Metadata
Analyzed At
May 1, 2026, 12:07 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fstannp%2F@44c65edde1c8fb3048cf1a1faf4be06f427ba42e
Security Audit — socket — stannp