stitch-design-md

Pass

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security vulnerabilities were detected in the skill instructions or examples.
  • [EXTERNAL_DOWNLOADS]: The skill references an upstream repository from a Google-owned GitHub organization. This is used for origin tracking and catalog normalization rather than unverified runtime code execution.
  • [DATA_EXFILTRATION]: The skill includes explicit security guidelines in the 'Anti-Patterns' section, specifically forbidding the reading, printing, or storing of Stitch API keys, MCP secrets, or credential-bearing files.
  • [COMMAND_EXECUTION]: Documentation provides instructions for the user to execute local helper scripts (e.g., 'scripts/export-gemini-skill.py') for environment-specific deployment. These are standard administrative actions and do not involve unauthorized or hidden execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 15, 2026, 06:06 PM
Security Audit — agent-trust-hub — stitch-design-md