stitch-to-react

Warn

Audited by Socket on Mar 9, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

The skill demonstrates coherent purpose-capability alignment for converting Stitch designs into React components with architecture enforcement. However, its dependency on external design artifact downloads and an internal fetch script introduces supply-chain and data-flow risks. The absence of explicit credential handling is positive, but the presence of download-and-run style steps (even if local) and reliance on potentially unverifiable external URLs justify labeling as SUSPICIOUS rather than BENIGN. Recommend tightening input validation, ensuring all external URLs and scripts come from trusted registries or enterprise sources, and adding explicit integrity checks (checksums, signatures) for downloaded assets. Consider adding explicit data flow controls and auditing logs to prevent inadvertent data leakage. Overall risk: suspicious with caveats leaning toward moderate risk if mitigations are implemented.

Confidence: 62%Severity: 50%
Audit Metadata
Analyzed At
Mar 9, 2026, 10:25 PM
Package URL
pkg:socket/skills-sh/acedergren%2Fagentic-tools%2Fstitch-to-react%2F@e8bb4b32e1bf80c6adabf021542ba0b4c998b2da