stitch-design-md

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest external and potentially untrusted artifacts (HTML, screenshots, metadata) to generate design instructions that guide the agent's future output, creating a multi-step injection surface.\n
  • Ingestion points: Step 1 of the workflow in SKILL.md explicitly directs the agent to gather screenshots, exported HTML, and design metadata.\n
  • Boundary markers: The instructions lack specific delimiters or guardrails to ensure the agent ignores instructions that may be embedded within these external source artifacts.\n
  • Capability inventory: The skill is configured to use Stitch MCP tools for operations like upload_design_md and apply_design_system, providing a pathway for processed data to reach external services.\n
  • Sanitization: There is no mention of sanitizing or validating the contents of the gathered artifacts before they are incorporated into the design system documentation.\n- [EXTERNAL_DOWNLOADS]: The skill's source and workflow are imported from a GitHub repository maintained by the Google Labs organization.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 03:52 AM
Security Audit — agent-trust-hub — stitch-design-md