stitch-uviewpro-components
Pass
Audited by Gen Agent Trust Hub on Jun 23, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill uses a local Bash script (
scripts/fetch-stitch.sh) to download design HTML from Stitch. The script is a simple wrapper forcurland targets Google Cloud Storage URLs provided by the Stitch MCP tool, which is a trusted source.- [SAFE]: The skill incorporates extensive documentation and mapping rules for the uView Pro framework, referencing the official and well-known service domainuviewpro.cn. No malicious domains or unknown external scripts are referenced.- [SAFE]: The skill defines a structured ingestion process for external design data. While processing external HTML represents a theoretical surface for indirect prompt injection, the skill is designed with specific mapping contracts and architectural checklists that mitigate the risk of unintended instruction execution.- [SAFE]: The skill's author ('full-stack-skills') uses internal resource patterns consistent with the provided author context, and all referenced repositories are part of the vendor's own ecosystem.
Audit Metadata