ui-workflow
Warn
Audited by Socket on Aug 8, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS. The core UI guidance is benign and aligned with its purpose, but the optional Stitch path materially expands trust: it installs a community MCP package, forwards Google credentials through it, and uses unpinned runtime package execution. This is not confirmed malware, but the credential forwarding and third-party proxying are inconsistent with a low-risk design workflow.
Confidence: 89%Severity: 72%
Audit Metadata