stigg-widgets
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides documentation and code examples for integrating official Stigg UI components using
@stigg/react-sdk,@stigg/js-client-sdk, and@stigg/vue-sdk. - [EXTERNAL_DOWNLOADS]: The skill instructs the agent to fetch a machine-readable index from
https://widgets.stigg.io/index.json. This is a vendor-owned domain used to discover component variants and is a standard operational procedure for this service. - [CREDENTIALS_UNSAFE]: The skill correctly handles sensitive information by instructing users to use only publishable client keys (prefixed with
client-) and explicitly warning against the use of server keys in client-side applications. It further recommends production hardening using HMAC SHA256 signed customer tokens.
Audit Metadata