stitch
Warn
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The
scripts/stitch.mjsscript performs dynamic loading of the@google/stitch-sdkmodule using theimport()function. The module path is computed at runtime based on theruntime.dirconfiguration, which defaults to the user's cache directory but can be modified via environment variables or CLI flags. - [COMMAND_EXECUTION]: The skill executes shell commands using
spawnSyncto manage the installation of its required SDK. It runsnpm installto bootstrap the@google/stitch-sdkpackage into a local runtime directory. - [EXTERNAL_DOWNLOADS]: The skill downloads external resources from the npm registry during its initialization phase. It also fetches design artifacts, such as HTML and images, from Google's Stitch service (
stitch.googleapis.com) using thefetchAPI during normal operation. - [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by processing data from several external sources without explicit sanitization.
- Ingestion points: The skill reads content from user-specified prompt files (
--prompt-file) and design system configuration files (--design-system-file). It also ingests output from the Stitch API. - Boundary markers: The instructions do not define or utilize boundary markers or special instructions to isolate ingested data from the core prompt logic.
- Capability inventory: The skill possesses capabilities including writing to the local file system, executing commands via
npm, and making network requests. - Sanitization: There is no evidence of content sanitization or validation performed on the ingested design payloads or prompt text before they are incorporated into operations.
Audit Metadata