stitch-react
Warn
Audited by Socket on Jun 25, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill's core purpose is coherent, and its external fetches to signed Google Cloud Storage URLs fit that purpose. The main risk is indirect prompt injection: it downloads untrusted HTML, reads it, and then has authority to edit code and run shell commands. The repo-local fetch script is also unverifiable from the provided content. No clear credential theft, stealth, or malicious exfiltration is present.
Confidence: 87%Severity: 68%
Audit Metadata