Back to skill

Security audit

Brand Frontend

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its landing-page purpose, but it directs the agent to install a changing external SDK globally and open generated files automatically without clear user approval.

Install only if you are comfortable with the agent using Google Stitch and creating local project artifacts. Before running it, prefer a project-local pinned SDK install, confirm any package-manager command, use a scoped STITCH_API_KEY, avoid providing sensitive screenshots or logos unless you want them saved in the bundle, and consider asking the agent to give you preview file paths instead of opening generated HTML automatically.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:39
Finding

Unpinned Autonomous Global SDK Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 39-44
Vulnerability Type: Unpinned third-party dependency installation from mutable external instructions
Risk Level: Medium

Vulnerable Code Snippet

text
1. Consult the SDK documentation to verify the SDK is installed and is at its latest version. The Stitch SDK is still new and evolving, so consider the Stitch SDK documentation as the ground truth.
2. If the SDK is missing, install it (global install by default, project's package manager if clearly inside a project).
3. Verify `STITCH_API_KEY` is set. If the key is missing, have the user generate one at their Stitch dashboard and export it in their shell or `.env`.
4. Make one minimal SDK call to confirm auth. Diagnose and retry once on failure before involving the user.

Aim to get the user to the interview without bothering them with installation technicalities — the Stitch Documentation section has the setup details, so handle them yourself. Never display, transcribe, or echo the key.

Technical Analysis

The Skill directs the Agent to consult mutable external documentation and autonomously install the latest Stitch SDK globally. It does not specify an exact package name, trusted registry, pinned version, integrity hash, lockfile, or validated installation command.

Treating external documentation as the current “ground truth” means the effective installation procedure can change after this Skill has been audited. Installing the latest package also prevents reproducible dependency resolution. If the documentation, linked domain, package account, registry entry, or dependency chain is compromised, the Agent could install a malicious package. Package installation hooks could then execute arbitrary code with the Agent process's operating-system permissions.

A global installation is broader than required for a single landing-page project. It can modify shared executables and package directories, affect unrelated projects, an ...[truncated 1762 chars]

Remediation
View remediation

Remediation Suggestions

  1. Specify the official SDK package name and approved registry explicitly rather than deriving installation commands from mutable documentation.
  2. Pin an audited SDK version instead of requesting the latest release.
  3. Record dependency resolution in a project lockfile and verify the package with a published integrity hash or signature.
  4. Install the SDK project-locally with the existing package manager rather than globally.
  5. Require explicit user confirmation before adding or upgrading any dependency.
  6. Disable package lifecycle scripts during installation where supported, then enable only reviewed build steps when necessary.
  7. Validate the package publisher, registry URL, resolved transitive dependencies, and downloaded integrity metadata before execution.
  8. Run SDK tooling with access limited to the current project and only the environment variables required for Stitch.
  9. Avoid placing STITCH_API_KEY in broadly readable project files; prefer a scoped secret mechanism or process environment with restrictive permissions.
  10. Document a reviewed installation command directly in the Skill so subsequent executions remain reproducible.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

MCP Config Access

High
Category
Agent Snooping
Confidence
80% confidence
Finding

Skill accesses MCP server configuration files (mcp.json). MCP configs contain server URLs, authentication tokens, and tool definitions — reading them allows the skill to discover and potentially abuse other tool integrations.

Content

Scanner excerpt · SKILL.md (reported line 48)May include surrounding context.

md
### SDK Usage Notes

- **Discover MCP tool names through the agent runtime.** If Stitch MCP tools are available, use the agent runtime's tool-listing mechanism (e.g., `list_tools`) to capture exact tool names. Names may be prefixed (e.g., `stitch_create_project`, `mcp__stitch__create_project`). Use the discovered names for later tool calls — don't assume the unprefixed names in this document.
- **Prefer the SDK's own response data over memory.** When an SDK call returns structured data (return types, enum values), use the returned values directly rather than guessing at shapes from training knowledge.
- **Fail fast, recover quietly.** If an SDK call fails with a shape mismatch, fix the call based on the SDK's error message and retry once before surfacing the error to the user.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill directs the agent to install software, verify environment variables, and make SDK calls on the user's behalf before any explicit confirmation. Those actions modify the local environment and can execute package-manager or shell operations that exceed the core design-interview function, increasing the risk of unintended system changes or dependency-chain exposure.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · SKILL.md (reported line 113)May include surrounding context.

md
### Image Handling

Do NOT ask the user to provide images or logos. Stitch does not accept image uploads via API.

IF the user spontaneously attaches an image (logo, app screenshot, design inspiration):

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill tells the agent to save user-provided files to .stitch/user-assets/ without clearly informing the user that their files will be persisted locally. Silent persistence can create privacy, retention, and data-handling issues, especially if the files contain proprietary branding assets or sensitive screenshots.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs the agent to open generated local HTML in the user's browser using OS-specific shell commands. Opening generated HTML can trigger active browser behavior, load external resources, or expose the user to unsafe content if the generated page includes malicious markup or scripts, and the shell invocation itself broadens the execution surface.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill directs the agent to open generated HTML automatically without warning the user that the file may contain active content or external references. While the HTML is locally generated, rendering it in a browser still creates a trust boundary issue and may surprise users who did not consent to execution-like preview behavior.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The stated purpose is to design and deliver a landing page bundle, but the implementation guidance specifically requires invoking the zip command. While packaging output is related to delivery, relying on shell command execution adds a host-execution capability not described in the manifest.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.