stitch-loop
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill is instructed to download HTML and image assets from remote URLs provided dynamically by the Stitch MCP server. These assets are saved locally to the project directory for integration.
- [COMMAND_EXECUTION]: The agent uses the
Bashtool to start a local development server (vianpx serve) to host and verify the generated website pages. - [INDIRECT_PROMPT_INJECTION]: The skill relies on an autonomous "baton-passing" loop where it reads the next task instructions from a file in the project directory (
.stitch/next-prompt.md). This ingestion of external data to drive agent behavior constitutes an indirect prompt injection surface. - Ingestion points: The agent parses
.stitch/next-prompt.md,.stitch/SITE.md, and.stitch/DESIGN.md(located inSKILL.md). - Boundary markers: The skill does not define explicit delimiters or use safety instructions to wrap the content read from the baton files.
- Capability inventory: The agent has access to
Bash(shell execution),Write/Read(file system access), and specialized MCP tools for generating content and controlling a browser (stitch*:*,chrome*:*). - Sanitization: The skill lacks sanitization or validation logic for the markdown and YAML content read from the project files before processing them as instructions.
Audit Metadata