stitch-mcp
Warn
Audited by Socket on Aug 18, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill’s core purpose is coherent, and direct use of Google Stitch MCP is benign, but the skill strongly prefers an unrelated third-party proxy/CLI that executes via `pnpx` and receives Stitch credentials. That credential-forwarding and supply-chain exposure are disproportionate when official Google endpoints and SDK paths already exist.
Confidence: 90%Severity: 82%
Audit Metadata