stitch-skills

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The core UI-design and screen-to-code capabilities are coherent with the stated purpose, and the Stitch-related data flow appears proportionate. The main risk is transitive trust: this skill instructs the agent to install additional skills via npx, including from an unrelated third-party GitHub repo, which expands the execution surface beyond the publisher and raises supply-chain risk. No strong evidence of credential theft or clearly malicious exfiltration is present, but the install footprint is broader than necessary.

Confidence: 83%Severity: 62%
Audit Metadata
Analyzed At
Apr 22, 2026, 12:46 PM
Package URL
pkg:socket/skills-sh/akillness%2Foh-my-skills%2Fstitch-skills%2F@55bc2860ac17182f0298864540cdd729f9511ecf