stitch

Warn

Audited by Socket on Sep 29, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/stitch.mjs

No explicit backdoor or classic malware behavior is evident in the shown fragment (no eval-style execution, reverse shells, or direct credential exfiltration code). However, the module’s primary security exposure is high-impact supply-chain execution: it installs an npm package at runtime based on user/environment-controlled parameters and then dynamically imports and executes code from the installed package. Separately, it downloads SDK-provided URLs to local files and may persist authentication fields into a local config file (secret-at-rest depends on whether upstream settings already blank credentials). Overall, treat this code as security-sensitive and require strict allowlisting/pinning of sdk-package/runtime-dir, integrity verification, URL/path validation, and guaranteed secret redaction before persistence.

Confidence: 60%Severity: 74%
Audit Metadata
Analyzed At
Sep 29, 2026, 10:10 AM
Package URL
pkg:socket/skills-sh/itamaker%2Fskills%2Fstitch%2F@2857b37df0213ea363f2b47fef4c3ee5650013d69c591d6e0d6f7d2ad4d8146d
Security Audit — socket — stitch