stitch-mcp-get-screen

Pass

Audited by Gen Agent Trust Hub on Jun 23, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill interacts with the 'stitch.google.com' domain, which is a well-known and trusted service for UI design management.
  • [SAFE]: Parameters such as 'projectId' and 'screenId' are extracted from user-provided paths using clearly defined logic that serves the skill's primary functional purpose.
  • [SAFE]: The 'Framework Conversion' process is implemented by reading local context and contracts (e.g., 'contract.md', 'component-api.md') from specific framework skills, ensuring the agent follows pre-defined implementation rules.
  • [SAFE]: The 'allowed-tools' configuration effectively restricts the agent's tool access to a necessary and expected scope for a design-to-code utility.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 23, 2026, 04:04 PM
Security Audit — agent-trust-hub — stitch-mcp-get-screen