skills/stiggio/skills/stigg-widgets/Gen Agent Trust Hub

stigg-widgets

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides documentation and code examples for integrating official Stigg UI components using @stigg/react-sdk, @stigg/js-client-sdk, and @stigg/vue-sdk.
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to fetch a machine-readable index from https://widgets.stigg.io/index.json. This is a vendor-owned domain used to discover component variants and is a standard operational procedure for this service.
  • [CREDENTIALS_UNSAFE]: The skill correctly handles sensitive information by instructing users to use only publishable client keys (prefixed with client-) and explicitly warning against the use of server keys in client-side applications. It further recommends production hardening using HMAC SHA256 signed customer tokens.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 07:04 AM
Security Audit — agent-trust-hub — stigg-widgets