stitch-generate-design

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: No malicious behavior, obfuscation, or persistence mechanisms detected. The skill instructions prioritize security by explicitly forbidding the storage or commitment of API keys and secrets.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided layout descriptions to build structured design prompts. Although this represents an ingestion point for untrusted data, the risk is minimized by the skill's focus on structural prompt generation rather than direct execution of user strings.\n
  • Ingestion points: User requests for design generation or edits (SKILL.md).\n
  • Boundary markers: Use of specific sections (Purpose, Platform, Structure) to delimit the generated output (examples/enhanced-prompt.md).\n
  • Capability inventory: MCP tools for design system management and project creation (SKILL.md).\n
  • Sanitization: Verification protocol requires structuring prompts by purpose and platform and avoiding blind repetition of tokens.\n- [EXTERNAL_DOWNLOADS]: The skill documentation identifies its source as a repository belonging to Google Labs. This reference is to a well-known and trusted organization.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 03:52 AM
Security Audit — agent-trust-hub — stitch-generate-design