stitch-mcp

Warn

Audited by Socket on May 13, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill's design purpose is coherent, but it disproportionately steers agents toward a non-Google proxy CLI as the primary path and routes API/OAuth handling through that third-party tool. Because the recommended CLI is external to Google and may receive credentials while performing broad setup/configuration, this is a high security risk supply-chain and credential-forwarding pattern, though not confirmed malware.

Confidence: 88%Severity: 84%
Audit Metadata
Analyzed At
May 13, 2026, 07:27 PM
Package URL
pkg:socket/skills-sh/baphomet480%2Fclaude-skills%2Fstitch-mcp%2F@acecb58d336e45cba5be328c7886b59c9ab36830