stitch-setup

Warn

Audited by Socket on Mar 21, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose is plausible and official Google endpoints are used for the MCP service, but the setup also asks users to trust unrelated third-party components: an NPX installer that may collect the API key and a separate GitHub-hosted skill/plugin repo. Those extra install paths are not clearly necessary for basic Stitch MCP setup and create supply-chain and transitive-trust risk disproportionate to a simple configuration guide.

Confidence: 85%Severity: 76%
Audit Metadata
Analyzed At
Mar 21, 2026, 02:43 AM
Package URL
pkg:socket/skills-sh/gabelul%2Fstitch-kit%2Fstitch-setup%2F@3afb1cebf69cf880225b3fdb1482f1521799b27e