← back to stitch-upload-to-stitch

SkillSpector · stitch-upload-to-stitch

independent scanner by NVIDIA · skill by oimiragieo · how it works ↗

WARNINGmax severity: HIGHrisk score: 56

The skill uses 'network' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.; Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credenti…; Output size or generation rate is not bounded. Unbounded output enables denial-of-service through resource exhaustion, log flooding, or context-window stuffing.

scanned 2026-08-23

Findings (3)

HIGHMCP Least Privilegeconfidence: 0.75

The skill uses 'network' capability that is not listed in its permissions. This may indicate deceptive intent or missing permission declarations.

scripts/upload_to_stitch.py

HIGHAgent Snoopingconfidence: 0.9

Skill reads from agent configuration directories (.claude/, .codex/, .gemini/). These directories may contain API keys, personal settings, and other credentials that the skill has no legitimate need to access.

SKILL.md

MEDIUMOutput Handlingconfidence: 0.75

Output size or generation rate is not bounded. Unbounded output enables denial-of-service through resource exhaustion, log flooding, or context-window stuffing.

scripts/upload_to_stitch.py

What the verdicts mean

SkillSpector reports on SkillMD's shared five-tier scale. See how SkillSpector works ↗.

PASS

Overall severity LOW (risk score in the safe range)

CAUTION

Overall severity MEDIUM

WARNINGthis skill

Overall severity HIGH

FAIL

Overall severity CRITICAL

INCONCLUSIVE

Scan could not complete