stitch-mcp-edit-screens
Warn
Audited by Socket on Jun 17, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s behavior is largely aligned with its stated purpose and shows no direct malicious or exfiltrative instructions, but its trust boundary is broader than the purpose suggests: it relies on a third-party Stitch MCP toolchain, and the granted `Bash/Read/Write` permissions are wider than needed for a simple design-edit workflow. Risk is primarily supply-chain and over-permissioning, not confirmed malware.
Confidence: 100%Severity: 60%
Audit Metadata