stitch-enhance-prompt

Pass

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a catalog-normalized import from an official repository belonging to a trusted organization (Google).
  • [CREDENTIALS_UNSAFE]: Contains explicit safety instructions (Anti-Patterns) that prohibit the agent from reading, printing, storing, or committing API keys, secrets, or credential-bearing files.
  • [SAFE]: The skill implements a 'Corrected Stitch MCP Surface' protocol, which limits the agent to only use tools that are explicitly verified and available in the host environment, preventing unauthorized or unexpected tool calls.
  • [PROMPT_INJECTION]: The skill processes user-provided UI requests to perform its primary function. While this constitutes an indirect prompt injection surface, the risk is mitigated by a structured workflow and a strict verification protocol.
  • Ingestion points: User UI requests and rough prompts (SKILL.md).
  • Boundary markers: The workflow relies on logical separation of layout, content, and behavior.
  • Capability inventory: MCP tools for project and design system management (SKILL.md).
  • Sanitization: Not explicitly specified, but instructions emphasize preserving user intent over external content.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 15, 2026, 06:06 PM
Security Audit — agent-trust-hub — stitch-enhance-prompt