stitch-mcp

Warn

Audited by Socket on Aug 18, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill’s core purpose is coherent, and direct use of Google Stitch MCP is benign, but the skill strongly prefers an unrelated third-party proxy/CLI that executes via `pnpx` and receives Stitch credentials. That credential-forwarding and supply-chain exposure are disproportionate when official Google endpoints and SDK paths already exist.

Confidence: 90%Severity: 82%
Audit Metadata
Analyzed At
Aug 18, 2026, 06:18 AM
Package URL
pkg:socket/skills-sh/genericservice%2Fclaude-skills%2Fstitch-mcp%2F@44514b8505348586fdc151a258acc2dc0165bab1048e88ceb1c4eac9a52dbf5a
Security Audit — socket — stitch-mcp