stitch-loop

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s core behavior matches its stated Stitch website-building purpose, and data flows are broadly consistent with official Stitch usage. Risk comes from autonomous looping, wildcard Stitch tool access, shell-based downloading of generated assets, and optional `npx` execution; these are proportionate to the task but still create meaningful security exposure for an AI agent.

Confidence: 87%Severity: 58%
Audit Metadata
Analyzed At
Mar 21, 2026, 02:43 AM
Package URL
pkg:socket/skills-sh/gabelul%2Fstitch-kit%2Fstitch-loop%2F@0a711b0d9dd79b6045b1cd60e3630b492a725d60
Security Audit — socket — stitch-loop