stitch-ui-designer

Pass

Audited by Gen Agent Trust Hub on Jun 23, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements a robust orchestration workflow that leverages specialized sub-skills (e.g., stitch-ui-design-spec-generator, stitch-ui-prompt-architect) for specific tasks, ensuring a clean and manageable design process.\n- [SAFE]: A critical safety prerequisite is defined, requiring explicit user mentions of "Stitch" before the skill is used, which prevents the agent from autonomously invoking powerful design tools without user intent.\n- [SAFE]: The allowed tools (stitch*:*, Read, Write, web_fetch) are consistent with the skill's purpose of orchestrating UI design projects and managing design-related assets.\n- [SAFE]: External dependencies on design contract tools (e.g., stitch-ui-design-spec-uview) follow the vendor resource pattern (full-stack-skills), representing legitimate functionality within the vendor's ecosystem without introducing unknown supply chain risks.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 23, 2026, 04:05 PM
Security Audit — agent-trust-hub — stitch-ui-designer