stitch-mcp-edit-screens

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill instructions do not contain any attempts to override safety protocols, bypass guidelines, or extract system prompts. The logic is focused entirely on the documented functionality of the Stitch service.
  • [DATA_EXFILTRATION]: No hardcoded credentials, sensitive file path access, or unauthorized network operations were detected. The skill uses standard tool-calling patterns for a specific design service.
  • [REMOTE_CODE_EXECUTION]: There are no patterns involving the download or execution of remote scripts. The skill operates through defined MCP tool calls.
  • [COMMAND_EXECUTION]: Although the skill specifies 'Bash', 'Read', and 'Write' in its allowed-tools list, the instructions do not use these tools for any dangerous or unauthorized operations. They are likely part of the agent's standard environment for processing design files.
  • [OBFUSCATION]: No obfuscated text, hidden characters, or encoded commands were found in the skill content.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a surface for indirect prompt injection as it processes suggestions (output_components) from a tool response. However, it requires user acceptance before acting on these suggestions, providing a human-in-the-loop safety checkpoint.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 12:02 PM
Security Audit — agent-trust-hub — stitch-mcp-edit-screens