stitch-design-md
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest external and potentially untrusted artifacts (HTML, screenshots, metadata) to generate design instructions that guide the agent's future output, creating a multi-step injection surface.\n
- Ingestion points: Step 1 of the workflow in
SKILL.mdexplicitly directs the agent to gather screenshots, exported HTML, and design metadata.\n - Boundary markers: The instructions lack specific delimiters or guardrails to ensure the agent ignores instructions that may be embedded within these external source artifacts.\n
- Capability inventory: The skill is configured to use Stitch MCP tools for operations like
upload_design_mdandapply_design_system, providing a pathway for processed data to reach external services.\n - Sanitization: There is no mention of sanitizing or validating the contents of the gathered artifacts before they are incorporated into the design system documentation.\n- [EXTERNAL_DOWNLOADS]: The skill's source and workflow are imported from a GitHub repository maintained by the Google Labs organization.
Audit Metadata