stitch-react

Warn

Audited by Socket on Jun 25, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill's core purpose is coherent, and its external fetches to signed Google Cloud Storage URLs fit that purpose. The main risk is indirect prompt injection: it downloads untrusted HTML, reads it, and then has authority to edit code and run shell commands. The repo-local fetch script is also unverifiable from the provided content. No clear credential theft, stealth, or malicious exfiltration is present.

Confidence: 87%Severity: 68%
Audit Metadata
Analyzed At
Jun 25, 2026, 03:03 AM
Package URL
pkg:socket/skills-sh/JoshuaShepherd%2Fmy-skills%2Fstitch-react%2F@dca1621f550cce017f5392b8326381229bdc94bf249882b5fa815ad3f217eaff
Security Audit — socket — stitch-react