skills/itamaker/stitch-skills/stitch/Gen Agent Trust Hub

stitch

Pass

Audited by Gen Agent Trust Hub on Apr 2, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses shell execution to manage its runtime environment.\n
  • The entry point scripts/run.sh executes the primary Node.js runner script.\n
  • In scripts/stitch.mjs, spawnSync is used to invoke npm install for bootstrapping the @google/stitch-sdk dependency.\n- [EXTERNAL_DOWNLOADS]: The skill retrieves code and data from external sources.\n
  • scripts/stitch.mjs installs the @google/stitch-sdk@0.0.3 package from the npm registry using the system's package manager.\n
  • The downloadUrlToFile function in scripts/stitch.mjs uses the global fetch API to download HTML and image artifacts from URLs returned by the Stitch service.\n- [REMOTE_CODE_EXECUTION]: The skill performs dynamic loading of executable content.\n
  • After installing the SDK package, the runner uses dynamic import() to load the SDK's logic from the installation directory into the current process.\n- [SAFE]: The skill handles authentication secrets with documented precautions.\n
  • Users can provide credentials via environment variables or CLI flags.\n
  • The save-config functionality allows persisting these parameters into a local .stitch.json file, and the documentation includes clear warnings to exclude this file from version control to prevent credential exposure.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 2, 2026, 05:01 AM
Security Audit — agent-trust-hub — stitch