stitch-mcp-get-project
Pass
Audited by Gen Agent Trust Hub on Mar 26, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues or malicious patterns were identified. The skill provides clear instructions for using the
get_projecttool to fetch design metadata from a trusted Google-owned domain (withgoogle.com). - [EXTERNAL_DOWNLOADS]: The skill references project metadata from
stitch.withgoogle.com. This domain is operated by a trusted organization and is used for legitimate project identification and metadata retrieval. - [DATA_EXFILTRATION]: There are no signs of unauthorized data access or exfiltration. The skill is limited to accessing UI design tokens and project structure as part of its intended design generation workflow.
Audit Metadata