stitch-mcp-delete-project

Pass

Audited by Gen Agent Trust Hub on Mar 21, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill defines a destructive action for project deletion but mandates explicit user confirmation and verification of the project metadata before proceeding, which is a security best practice.
  • [SAFE]: Analysis of potential indirect prompt injection surface in SKILL.md: 1. Ingestion points: The skill processes project IDs likely retrieved from other tool outputs. 2. Boundary markers: No explicit technical markers, but strict instructional boundaries require user confirmation. 3. Capability inventory: Uses MCP tools delete_project and get_project. 4. Sanitization: Instructs the agent to fetch and display the project title to the user before deletion to ensure accuracy.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 21, 2026, 02:41 AM