stitch
Pass
Audited by Gen Agent Trust Hub on Sep 29, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill downloads the
@google/stitch-sdkpackage from the public npm registry. The source organization is categorized as trusted. - [COMMAND_EXECUTION]: The
scripts/stitch.mjsrunner script executes thenpm installcommand to bootstrap the necessary design SDK into a local cache directory. - [DYNAMIC_EXECUTION]: The utility uses dynamic Node.js
import()calls to load the Stitch SDK from a path resolved at runtime in the user's cache folder. - [INDIRECT_PROMPT_INJECTION]: The skill provides an interface to pass user-defined text prompts to the Stitch service for design generation, which is a standard surface for indirect injection.
- Ingestion points: Input is accepted through the
--promptand--prompt-filearguments in the CLI runner. - Boundary markers: The skill does not implement specific delimiters or instructions to isolate the user input from the service's internal prompt logic.
- Capability inventory: The skill can perform network requests (downloading design assets), write files (config and design output), and execute subprocesses (npm).
- Sanitization: The prompts are passed to the SDK without explicit sanitization or validation filtering.
Audit Metadata