threat-stack

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s purpose is coherent, and its main dependency comes from an official registry in the same vendor ecosystem, so this is not overt malware. However, it routes Threat Stack authentication and data through Membrane as a third-party intermediary, expanding credential and data exposure beyond what a direct Threat Stack integration would require; combined with unpinned CLI execution, this makes the skill medium risk.

Confidence: 82%Severity: 58%
Audit Metadata
Analyzed At
Apr 28, 2026, 11:53 PM
Package URL
pkg:socket/skills-sh/membranedev%2Fapplication-skills%2Fthreat-stack%2F@ed55457d5e522d59fb7384e2ded8b8612e33892a
Security Audit — socket — threat-stack