stitch-uviewpro-components

Pass

Audited by Gen Agent Trust Hub on Jun 23, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill uses a local Bash script (scripts/fetch-stitch.sh) to download design HTML from Stitch. The script is a simple wrapper for curl and targets Google Cloud Storage URLs provided by the Stitch MCP tool, which is a trusted source.- [SAFE]: The skill incorporates extensive documentation and mapping rules for the uView Pro framework, referencing the official and well-known service domain uviewpro.cn. No malicious domains or unknown external scripts are referenced.- [SAFE]: The skill defines a structured ingestion process for external design data. While processing external HTML represents a theoretical surface for indirect prompt injection, the skill is designed with specific mapping contracts and architectural checklists that mitigate the risk of unintended instruction execution.- [SAFE]: The skill's author ('full-stack-skills') uses internal resource patterns consistent with the provided author context, and all referenced repositories are part of the vendor's own ecosystem.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 23, 2026, 04:04 PM
Security Audit — agent-trust-hub — stitch-uviewpro-components