stitch
Pass
Audited by Gen Agent Trust Hub on Apr 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses shell execution to manage its runtime environment.\n
- The entry point
scripts/run.shexecutes the primary Node.js runner script.\n - In
scripts/stitch.mjs,spawnSyncis used to invokenpm installfor bootstrapping the@google/stitch-sdkdependency.\n- [EXTERNAL_DOWNLOADS]: The skill retrieves code and data from external sources.\n scripts/stitch.mjsinstalls the@google/stitch-sdk@0.0.3package from the npm registry using the system's package manager.\n- The
downloadUrlToFilefunction inscripts/stitch.mjsuses the globalfetchAPI to download HTML and image artifacts from URLs returned by the Stitch service.\n- [REMOTE_CODE_EXECUTION]: The skill performs dynamic loading of executable content.\n - After installing the SDK package, the runner uses dynamic
import()to load the SDK's logic from the installation directory into the current process.\n- [SAFE]: The skill handles authentication secrets with documented precautions.\n - Users can provide credentials via environment variables or CLI flags.\n
- The
save-configfunctionality allows persisting these parameters into a local.stitch.jsonfile, and the documentation includes clear warnings to exclude this file from version control to prevent credential exposure.
Audit Metadata