stitch-enhance-prompt
Pass
Audited by Gen Agent Trust Hub on Jul 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a catalog-normalized import from an official repository belonging to a trusted organization (Google).
- [CREDENTIALS_UNSAFE]: Contains explicit safety instructions (Anti-Patterns) that prohibit the agent from reading, printing, storing, or committing API keys, secrets, or credential-bearing files.
- [SAFE]: The skill implements a 'Corrected Stitch MCP Surface' protocol, which limits the agent to only use tools that are explicitly verified and available in the host environment, preventing unauthorized or unexpected tool calls.
- [PROMPT_INJECTION]: The skill processes user-provided UI requests to perform its primary function. While this constitutes an indirect prompt injection surface, the risk is mitigated by a structured workflow and a strict verification protocol.
- Ingestion points: User UI requests and rough prompts (SKILL.md).
- Boundary markers: The workflow relies on logical separation of layout, content, and behavior.
- Capability inventory: MCP tools for project and design system management (SKILL.md).
- Sanitization: Not explicitly specified, but instructions emphasize preserving user intent over external content.
Audit Metadata