Stitch AutoCAUTION
Automated installer for Stitch MCP - The easiest way to set up your Universal MCP server for Google Stitch.
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
English | 한국어
One command. Instant UI. The most automated MCP server for Google Stitch.
💡 Just share this link with your AI: https://github.com/GreenSheep01201/stitch-mcp-auto
Why stitch-mcp-auto?
Features:
- Auto Setup - One command installs everything (gcloud auth, API enable, MCP config)
- Multi-CLI Support - Works with Claude Code, Gemini CLI, Codex CLI
- 19 Custom Tools + Stitch Core - Design generation, accessibility checks, tokens, responsive variants, and design system export
- 7 Workflow Commands -
/design,/design-system,/design-flow,/design-qa,/design-export,/generate-asset,/design-full - 🎨 AI Image Generation - Generate logos, icons, hero images via Gemini 3 Pro (uses Antigravity - Google's experimental
dc4fe0213300OBSERVED · 2026-10-08Connect
Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control.
claude mcp add stitch-mcp-auto -- npx -y [email protected]
{
"mcpServers": {
"stitch-mcp-auto": {
"command": "npx",
"args": [
"-y",
"[email protected]"
]
}
}
}Exposed tools (33)
29 read · 3 write · 1 destructive. Blast radius: 1 tool can delete or overwrite — an agent that can be talked into calling a tool can be talked into calling this one.
| Tool | Risk | Description |
|---|---|---|
analyze_accessibility | read | Analyzes a screen for WCAG 2.1 accessibility compliance. Checks color contrast, text sizes, touch targets, semantic structure, and provides actionable recommendations. |
apply_design_context | write | Generates a new screen using a previously extracted design context to ensure visual consistency. Combines the power of design context with a new screen description. |
batch_generate_screens | read | Generates multiple related screens in a single operation with consistent design language. Ideal for creating complete user flows or page sets. |
check_antigravity_auth | read | Checks Antigravity (Gemini 3 Pro) auth status. Required for image asset generation (logo, icon, illustration). Stitch auth (gcloud) is separate and used for UI page generation. |
clear_workspace_project | destructive | 🗑️ Removes the Stitch project association from the current workspace/folder. Use this when the user wants to start fresh or switch to a different project. |
compare_designs | read | Compares two screens to identify design differences, inconsistencies, and suggest harmonization opportunities. Useful for design system audits. |
component_format | read | Component format: react, vue, html, json |
design | read | Smart UI design generation with automatic style detection and trend application |
design-export | read | Generate design system packages for developer handoff (tokens, components, docs) |
design-flow | read | Generate multiple screens for complete user flows with consistent design |
design-qa | read | Comprehensive design quality, accessibility (WCAG 2.1), and consistency checks |
design-system | write | Create new screens while maintaining existing design style for brand consistency |
device | read | Device type: MOBILE, DESKTOP, or TABLET |
export_design_system | read | Exports a complete design system package from project screens including tokens, components, documentation, and assets. Ready for developer handoff. |
extract_components | read | Extracts reusable UI component patterns from a screen. Identifies buttons, cards, forms, navigation elements, etc. with their styles and variants. |
extract_design_context | read | Extracts design DNA from an existing screen including colors, typography, spacing, layout patterns, and component styles. Use this to maintain visual consistency across multiple screens. |
fetch_screen_code | read | Retrieves the actual HTML/Code content of a screen. |
fetch_screen_image | read | Retrieves the screenshot/preview image of a screen. |
flow | read | Flow description (e.g., |
generate_design_asset | read | 🎨 Generates design assets (logo, icon, illustration, hero image, wireframe) using Gemini via Antigravity OAuth. Supports gemini-3-pro (default), gemini-2.5-pro. Use check_antigravity_auth to verify auth status first. |
generate_design_tokens | read | Generates design tokens (CSS variables, Tailwind config, or design system JSON) from an existing screen |
generate_responsive_variant | read | Creates a responsive variant of an existing screen for a different device type while maintaining the same design language and content. |
generate_style_guide | read | Generates a comprehensive style guide/design documentation screen from an existing design. Creates a visual reference of colors, typography, components, and usage guidelines. |
get_workspace_project | read | 🔍 Checks if there is an existing Stitch project associated with the current workspace/folder. Returns project info if found, or null if no project is set. Use this at the start of a session to check for existing projects and ask the user if they want to continue with it. |
level | read | WCAG level: A, AA, or AAA |
orchestrate_design | read | 🎭 Full design orchestration: Generates assets (logo, icons, hero) via Antigravity/Gemini 3 Pro with auto background removal, then creates complete UI with Stitch API. Requires both Stitch (gcloud) and Antigravity auth for full functionality. One prompt to complete design! |
prompt | read | Screen description (e.g., |
reference_screen_id | read | Screen ID to use as design reference |
screen_id | read | Screen ID to analyze (or |
set_workspace_project | write | 💾 Associates a Stitch project with the current workspace/folder. This allows continuing work on the same project in future sessions. The project info is stored in .stitch-project.json in the current directory. |
style | read | Design style: glassmorphism, dark, minimal, bento-grid, etc. |
suggest_trending_design | read | Suggests and applies modern UI/UX design trends to a screen prompt. Includes glassmorphism, bento-grid, gradient meshes, micro-interactions, and more. |
token_format | read | Token format: css-variables, tailwind, scss, json |
Trust audit
CAUTIONgrade B · trust 89/100 Install with care. The audit found things worth knowing before you trust its output.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | WARN |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- declared (3 observation(s))
- Network
- declared (5 observation(s))
- Shell
- declared (5 observation(s))
- Dependencies
- not all pinned
- Secrets in source
- none-found
Findings (10)
'/usr/local/bin/gcloud',
'/usr/local/bin/gcloud',
clear_workspace_project
@modelcontextprotocol/sdk, googleapis, node-fetch, open, sharp
# Add to PATH
curl -o- https://raw.githubusercontent.com/nvm-sh/nvm/v0.40.1/install.sh | bash
curl https://sdk.cloud.google.com | bash
curl -sSL https://sdk.cloud.google.com | bash -s -- --disable-prompts --install-dir=$HOME
curl -o- https://raw.githubusercontent.com/nvm-sh/nvm/v0.40.1/install.sh | bash
curl https://sdk.cloud.google.com | bash
Gates applied: no_behavioural_pass.
dc4fe0213300full audit observations/trust-audit/mcp-server/greensheep01201__stitch-auto.json · Report an issue / request a re-scanAudit history
Every audit this server has had. A grade with a past is a grade somebody is still checking.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | dc4fe0213300 | CAUTION | B | 89 | first audit |
Questions
What is the Stitch Auto MCP server?
Automated installer for Stitch MCP - The easiest way to set up your Universal MCP server for Google Stitch.
What tools does Stitch Auto expose?
33 in total: 29 read-only, 3 that write, and 1 that can delete or overwrite (clear_workspace_project). Every one is listed on this page with its risk.
Is Stitch Auto safe to connect to an agent?
With care. The audit graded it B (89/100) and found 10 things worth knowing before you trust this server, listed below with the exact line each was found on. Separately from the audit: 1 of its tools can destroy data, so scope the token you give it to what you actually need.
What credentials does Stitch Auto need?
No credential environment variables were found in its source, so it appears to need none.
How does Stitch Auto run?
It speaks stdio, so it runs as a local process your client starts. It is published on npm as stitch-mcp-auto at 1.2.2.
How current is this page?
The grade is for one exact copy of the source (dc4fe0213300), read on 2026-10-08. The repository is watched and re-audited when it changes.