stitch

Warn

Audited by Socket on Apr 23, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the skill's stated purpose is coherent, but its trust chain is not. It claims to use an official Google Stitch CLI while directing the agent to execute an unscoped npm package name that does not match the provided official SDK evidence, then feed it API keys/OAuth tokens and perform remote mutations. This is a supply-chain and credential-forwarding risk rather than confirmed malware.

Confidence: 84%Severity: 72%
Audit Metadata
Analyzed At
Apr 23, 2026, 07:42 AM
Package URL
pkg:socket/skills-sh/danielgwilson%2Fstitch-design-cli%2Fstitch%2F@71e62a260313d7e3030f2d6a17067c455c7f4873