stitch-design-system
Pass
Audited by Gen Agent Trust Hub on Apr 3, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill uses
web_fetchto retrieve project assets fromwithgoogle.comdomains. These are identified as trusted, well-known service endpoints for the Google Stitch platform.\n- [SAFE]: No evidence of hardcoded credentials, malicious persistence, or unauthorized command execution was found in the instructions or the accompanying test suite.\n- [SAFE]: The analysis workflow is limited to processing design metadata and visual properties to generate aDESIGN.mdfile, maintaining a safe operational scope with no exfiltration patterns.
Audit Metadata