stitch-loop
Pass
Audited by Gen Agent Trust Hub on Jul 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements strong defensive measures, such as explicit anti-patterns that instruct the agent to never read, print, store, or commit API keys, secrets, or credential-bearing files.
- [SAFE]: Instructions are provided for a fallback path in case specific tools are unavailable, promoting transparency and user oversight.
- [PROMPT_INJECTION]: No malicious prompt injection or behavior override patterns were detected. The instructions focus on structured workflow and verification.
- [DATA_EXFILTRATION]: No exfiltration patterns found. The skill operates on local site files and specific MCP tools for design systems.
- [REMOTE_CODE_EXECUTION]: No remote code execution patterns or downloads from untrusted sources detected. References to external repositories point to well-known/trusted organizations.
- [COMMAND_EXECUTION]: No dangerous or arbitrary command execution logic found. Mentions of local scripts are for project maintenance and within standard development practice.
Audit Metadata