stitch-enhance-prompt

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user input (rough UI requests) to generate enhanced prompts, which creates a potential surface for indirect prompt injection if the input contains malicious instructions. * Ingestion point: User-provided text requests described in the workflow section of SKILL.md. * Boundary markers: No specific delimiters or instructions to disregard embedded commands are mandated for the input. * Capability inventory: The skill relies on design-system tools (e.g., list_design_systems, apply_design_system) which lack high-risk capabilities like file system writing, privilege escalation, or network exfiltration. * Sanitization: No input validation or filtering is described for the processed requests.
  • [SAFE]: The skill documentation references external source material from a well-known organization (Google Labs). The skill also contains explicit security best practices, such as an anti-pattern against reading, printing, or storing Stitch API keys, cookies, or other credential-bearing files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 03:52 AM
Security Audit — agent-trust-hub — stitch-enhance-prompt