stitch::upload-to-stitch — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited stitch::upload-to-stitch (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Upload local assets (images, mockups, HTML, and markdown files) to a Stitch project using the provided upload script, which bypasses the MCP tool's base64 output token limits.
[!NOTE] The AI model cannot upload files via MCP tools directly because the base64 encoding of even a small file exceeds the model's output token limit (~16K tokens). This script reads the file and sends it directly over HTTP.
Use list_projects to find the correct projectId.
Locate your active MCP server configuration file and extract the API key:
.gemini/antigravity/mcp_config.json or .gemini/jetski/mcp_config.json~/.gemini/settings.json or ~/.gemini/extensions/Stitch/gemini-extension.json~/.claude.jsonExtract:
X-Goog-Api-Key header or auth argumenthttpUrl or endpoint argument (defaults tohttps://stitch.googleapis.com)
[!IMPORTANT] If you cannot find the API key in any of these locations, or if you cannot access these files, you MUST ask the user to provide the Stitch API key. Do not proceed without a valid API key.
[!WARNING] Checkpoint — User Confirmation Required. Before running the upload script, you MUST pause and present the file(s) to be uploaded (paths, sizes, and types) to the user and wait for explicit approval. Do NOT execute the upload script until the user confirms.
Use run_command to execute the Python script:
python3 <SKILL_DIR>/scripts/upload_to_stitch.py \
--project-id <PROJECT_ID> \
--file-path <PATH_TO_FILE> \
--api-key <API_KEY> \
[--api-url <STITCH_API_URL>] \
[--title <SCREEN_TITLE>] \
[--generated-by <GENERATED_BY>][!TIP] macOS / SSL Certificate Troubleshooting: If the upload fails with ssl.SSLCertVerificationError: [SSL: CERTIFICATE_VERIFY_FAILED] unable to get local issuer certificate, this means your Python installation does not have root certificate authorities configured.>
The script automatically attempts to use thecertifipackage to load the CA bundle if it is installed in your python environment. Ifcertifiis not installed, you can either install it (pip install certifi) or manually supply theSSL_CERT_FILEenvironment variable when running the script: ``bash SSL_CERT_FILE=$(python3 -c "import certifi; print(certifi.where())") python3 <SKILL_DIR>/scripts/upload_to_stitch.py \ --project-id <PROJECT_ID> \ --file-path <PATH_TO_FILE> \ --api-key <API_KEY> \ [--api-url <STITCH_API_URL>] \ [--title <SCREEN_TITLE>] \ [--generated-by <GENERATED_BY>]``
| Extension | MIME Type |
|---|---|
.png | image/png |
.jpg, .jpeg | image/jpeg |
.webp | image/webp |
.html, .htm | text/html |
.md | text/markdown |
The script auto-detects MIME type from the file extension.
--project-id: Required. The Stitch project ID.--file-path: Required. Path to the local file to upload.--api-key: Required. API key for Stitch authorization.--api-url: Optional. Base URL of the Stitch API. Defaults to https://stitch.googleapis.com.--title: Optional. Title for the uploaded screen.--generated-by: Optional. Specify how the uploaded file was generated (e.g., 'stitch::extract-static-html' skill, 'Claude Code', 'Codex', 'Gemini' etc.).~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.