stitch-mcp-edit-screens

Warn

Audited by Socket on Jun 17, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s behavior is largely aligned with its stated purpose and shows no direct malicious or exfiltrative instructions, but its trust boundary is broader than the purpose suggests: it relies on a third-party Stitch MCP toolchain, and the granted `Bash/Read/Write` permissions are wider than needed for a simple design-edit workflow. Risk is primarily supply-chain and over-permissioning, not confirmed malware.

Confidence: 100%Severity: 60%
Audit Metadata
Analyzed At
Jun 17, 2026, 12:03 PM
Package URL
pkg:socket/skills-sh/findbene%2Fskills%2Fstitch-mcp-edit-screens%2F@e9dcd0e35e63b749ec27ae89daa26f1d044724aaefca283d0f1b70b0d1b449bd
Security Audit — socket — stitch-mcp-edit-screens