stitch-design-md
Pass
Audited by Gen Agent Trust Hub on Jul 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security vulnerabilities were detected in the skill instructions or examples.
- [EXTERNAL_DOWNLOADS]: The skill references an upstream repository from a Google-owned GitHub organization. This is used for origin tracking and catalog normalization rather than unverified runtime code execution.
- [DATA_EXFILTRATION]: The skill includes explicit security guidelines in the 'Anti-Patterns' section, specifically forbidding the reading, printing, or storing of Stitch API keys, MCP secrets, or credential-bearing files.
- [COMMAND_EXECUTION]: Documentation provides instructions for the user to execute local helper scripts (e.g., 'scripts/export-gemini-skill.py') for environment-specific deployment. These are standard administrative actions and do not involve unauthorized or hidden execution.
Audit Metadata