stitch-mcp-get-project
Pass
Audited by Gen Agent Trust Hub on Jun 23, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill retrieves configuration and project metadata from
stitch.withgoogle.com, which is an official domain owned by a trusted organization. - [PROMPT_INJECTION]: The instructions include operational safeguards, such as requiring an explicit user mention of "Stitch" before tool invocation, which helps prevent unintended execution in complex dialogues.
- [COMMAND_EXECUTION]: The skill uses the
stitch*:*toolset and standard file tools (Read,Write) for their intended purposes of project management and metadata retrieval. - [PROMPT_INJECTION]: (Indirect) The skill processes project metadata like titles and theme descriptions. While this data is potentially user-controlled and represents a surface for indirect instructions, the integration targets a trusted service and does not exhibit malicious intent.
Audit Metadata