stitch-uviewpro-components

Pass

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill includes a bash script scripts/fetch-stitch.sh that uses curl to download design metadata and HTML content from URLs provided by the Stitch MCP server. This is a core part of the workflow for retrieving remote design files from Google Cloud Storage.
  • [COMMAND_EXECUTION]: The skill uses the Bash tool to execute a local utility script for high-reliability fetching. This execution is scoped to the provided script and is used for its intended purpose of handling network redirects and timeouts during asset retrieval.
  • [DATA_EXFILTRATION]: No data exfiltration patterns were detected. Network operations are limited to fetching design content from the authorized Stitch design platform.
  • [PROMPT_INJECTION]: The skill processes external HTML data from Stitch designs to generate code. While this represents an indirect prompt injection surface typical of conversion tools, the skill provides specific architectural rules and component contracts to guide the AI's output, reducing the risk of malicious instructions in the design data influencing the agent's behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 13, 2026, 04:13 AM
Security Audit — agent-trust-hub — stitch-uviewpro-components