stitch-mcp-cli
Warn
Audited by Socket on May 17, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill’s capabilities mostly match its stated Stitch-to-dev-workflow purpose, and data flow is broadly consistent with Google/Stitch integration. However, trust is weakened because ara.so publishes the skill while users are instructed to execute a third-party personal npm package that may install and manage gcloud/auth locally, with runtime npx execution and limited install-verification details.
Confidence: 84%Severity: 63%
Audit Metadata