pencil-design-from-stitch-html
Pass
Audited by Gen Agent Trust Hub on Jun 23, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructions describe fetching HTML assets from Stitch URLs (provided via the Stitch MCP tool). These downloads target a well-known service and are a core part of the design conversion workflow.
- [COMMAND_EXECUTION]: The skill utilizes the Bash tool for routine file management tasks, such as downloading and saving temporary HTML files for parsing.
- [PROMPT_INJECTION]: The skill's instructions were analyzed for override or bypass patterns; no malicious injection attempts were detected. The content is focused on technical UI element mapping and execution planning.
- [DATA_EXFILTRATION]: No patterns of sensitive data access or unauthorized exfiltration were identified. Network operations are limited to fetching design prototypes as intended.
- [SAFE]: The skill consists of documentation and reference tables designed to guide the agent in using approved MCP tools for UI transformation tasks.
Audit Metadata