Official agent skill

Stitch SDK Bug Bash

by google-labs-code in google-labs-code/stitch-sdk

Find bugs in the Stitch SDK using a real API key. An agent skill from google-labs-code/stitch-sdk.

OfficialApache-2.0Auto-check passedDevelopment

Install Stitch SDK Bug Bash

skills CLI
$ npx skills add google-labs-code/stitch-sdk --skill stitch-sdk-bug-bash -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install google-labs-code/stitch-sdk stitch-sdk-bug-bash --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/google-labs-code/stitch-sdk.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/stitch-sdk-bug-bash .claude/skills/stitch-sdk-bug-bash && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
stitch-sdk-bug-bash
GitHub stars
1.8k
Token cost
~1.6k tokens
SKILL.md length
476 words
Files
1
Skills in repo
9
Repo updated
First seen
Licence
Apache-2.0

At a glance

Find bugs in the Stitch SDK using a real API key. An agent skill from google-labs-code/stitch-sdk.

  • Works in 4 steps: Root & Initialization (Stitch) → Project Lifecycle (Project) → Screen Lifecycle (Screen) → …
  • Tasks that involve Debugging
  • SKILL.md covers The Mindset: Adversarial…, Surface Areas to Cover, Tricky Situations Matrix… and Diagnostic Hygiene, plus 1 more section
  • Needs STITCH_API_KEY

What it does

Stitch SDK Bug Bash is an agent skill from google-labs-code/stitch-sdk, published by the product's own GitHub organization. Find bugs in the Stitch SDK using a real API key. Covers standard functional edges and tricky situations.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Debugging. It works with Bash. The repository describes itself as: Generate UI screens from text prompts and extract their HTML and screenshots programmatically. The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Debugging

Example prompts

  • “/stitch-sdk-bug-bash”

Requirements

  • A credential in STITCH_API_KEY

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Root & Initialization (Stitch)
  2. Project Lifecycle (Project)
  3. Screen Lifecycle (Screen)
  4. Design System (DesignSystem)

What it can do on your machine

Read from SKILL.md and the folder at commit e3f8ece. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are typescript).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • STITCH_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Stitch SDK Bug Bash loads about 1.6k tokens when it runs. Until then it costs about 31 tokens; SKILL.md has 476 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~31
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from google-labs-code/stitch-sdk at commit e3f8ece, republished under its Apache-2.0 licence (© google-labs-code). 476 words, ~1,570 tokens.

Download SKILL.mdSave it as .claude/skills/stitch-sdk-bug-bash/SKILL.md (or your agent's skills folder).
name
stitch-sdk-bug-bash
description
Find bugs in the Stitch SDK using a real API key. Covers standard functional edges and tricky situations.

Stitch SDK Bug Bash

This skill provides a framework and instructions for finding bugs in the Stitch SDK using a real API key. It guides you through exploring standard functional edge cases and tricky situations beyond the golden path.


The Mindset: Adversarial Exploration

When using this skill, do not just verify that the SDK works. Try to break it!

  • Pass invalid or boundary parameters.
  • Attempt operations on deleted or stale handles.
  • Simulate unexpected API responses if possible or find edge cases where projection might fail.

Surface Areas to Cover

1. Root & Initialization (Stitch)
  • Zero Config: Verify the singleton works without explicit config if STITCH_API_KEY is present.
  • Invalid Config: Pass an empty API key or invalid base URL to StitchToolClient and verify that the first call fails with a clear authentication or connection error, not a generic noise error.
2. Project Lifecycle (Project)
  • Handle Creation: Verify that stitch.project('invalid-id') does not throw (lazy instantiation) but the first call on it fails safely.
  • Factory vs API: Verify that creating a project handle via the factory doesn't trigger API calls, but methods like project.listScreens() do.
3. Screen Lifecycle (Screen)
  • The Handover: Verify that properties from Project.generate() are correctly populated on the returned Screen instances without a second fetch.
  • Null Safety in Projections: Test tools or scenarios that return empty arrays or missing optional fields. Verify that the SDK handle handles them as undefined or empty arrays rather than crashing on null property access!
4. Design System (DesignSystem)
  • Application: Create a design system, and apply it to a list of screens. Verify that if the list is empty or invalid, the SDK fails cleanly!
  • Handles: Verify that project.designSystem('ds-id') correctly receives the projectId and injects it into calls like ds.apply(...).

Show full SKILL.md (192 more words)Show less

Tricky Situations Matrix (Standard Functional Edges)

ScenarioWhat to tryExpected Behavior
Stale HandlesCreate a screen, delete the project, then try to edit the screen handle.Clean API error indicating resource not found, wrapped in StitchError.
Empty PromptsCall project.generate('') or with only whitespace.Safe rejection or clear API error, no crash in codegen.
Projections on nullForce an API call that returns a response without the expected projection field (if you can simulate or find such a tool fallback case).The SDK should use optional chaining (e.g., raw?.prop) and return undefined rather than throwing TypeError: cannot read property of undefined.
Massive arraysPass hundreds of screen IDs to ds.apply().Check if it hits payload limits gracefully or fails with a clear message.

Diagnostic Hygiene

  • Always wrap your test calls in try/catch.
  • Log the error and inspect error.code or error.name to see if it's a StitchError or a generic raw error.
  • If an execution throws a raw TypeError or "cannot read property of undefined", that is a HIGH PRIORITY BUG in the SDK's projection logic!

Test Template: The Full Workflow Bash

Use this template to run a quick end-to-end bash session.

typescript
import { stitch } from "@google/stitch-sdk";

async function bash() {
  const apiKey = process.env.STITCH_API_KEY;
  if (!apiKey) throw new Error("STITCH_API_KEY is required");

  console.log("🚀 Starting Bug Bash...");

  let project;
  try {
    // 1. Create a fresh project
    project = await stitch.createProject({
      displayName: `Bug Bash ${new Date().toISOString()}`,
    });
    console.log(`✓ Created Project: ${project.id}`);

    // 2. Try to break generate with empty prompt
    try {
      await project.generate({ prompt: "" });
      console.log("✗ BUG: Generate with empty prompt should have failed!");
    } catch (e) {
      console.log("✓ Generate with empty prompt failed safely as expected.");
    }

    // 3. Create a design system
    const ds = await project.createDesignSystem({
      name: "Bash Style",
      variables: { primaryColor: "#ff0000" },
    });
    console.log(`✓ Created Design System: ${ds.id}`);

    // 4. List screens (should be empty)
    const screens = await project.listScreens();
    console.log(`✓ Listed screens: found ${screens.length}`);

    // 5. Apply design system to empty list
    try {
      await ds.apply({ selectedScreenIds: [] });
      console.log("✓ Applied design system to empty list (handled).");
    } catch (e) {
      console.log("✗ Did applying to empty list fail? Inspect error.");
    }
  } catch (error) {
    console.error("💥 Bash failed with error:", error);
  } finally {
    // 6. Cleanup
    if (project) {
      console.log(`🧹 Cleaning up project ${project.id}...`);
      // Assuming we have a deleteProject binding or we just leave it if not available
      // await project.delete();
    }
  }
}

bash();

© google-labs-code, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/stitch-sdk-bug-bash of google-labs-code/stitch-sdk.

Open the folder on GitHubat commit e3f8ece

Compare with similar skills

Stitch SDK Bug Bash next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Stitch SDK Bug Bash compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Stitch SDK Bug Bash this skillgoogle-labs-code/stitch-sdk1.8k—~1.6kAutomated safety check: PassApache-2.0
Ue Live DebuggingJasonMa0012/MooaToon749—~2.9kAutomated safety check: NotesCustom licence
Trace And Isolaterohitg00/skillkit1.5k—~1.8kAutomated safety check: PassApache-2.0
Cppcrazyguitar/cppcheatsheet290—~1.8kAutomated safety check: PassMIT
Code ChangesJanDeDobbeleer/oh-my-posh24k—~1.2kAutomated safety check: PassMIT
Opsmill Dev Fixing Bugsopsmill/infrahub529—~3.4kAutomated safety check: PassApache-2.0

Similar skills

  • Ue Live Debugging

    JasonMa0012/MooaToon

    A skill your agent uses when debugging UE C++ crashes, runtime bugs, or unexpected behavior with Rider MCP available.

    749 GitHub stars~2.9k tokensUpdated 19 days ago
    DevelopmentAuto-check: notes
  • Trace And Isolate

    rohitg00/skillkit

    Applies systematic tracing and isolation techniques to pinpoint exactly where a bug originates in code.

    1.5k GitHub stars~1.8k tokensUpdated 4 mo ago
    DevelopmentAuto-check passed
  • Cpp

    crazyguitar/cppcheatsheet

    Comprehensive C/C++ programming reference covering everything from C11-C23 and C++11-C++23, system programming, CUDA GPU computing, debugging tools, Rust interop, and advanced topics.

    290 GitHub stars~1.8k tokensUpdated 6 days ago
    DevelopmentAuto-check passed
  • Code Changes

    JanDeDobbeleer/oh-my-posh

    Orchestration workflow for any task that ends in code changes: issue analysis, pull request review, feature implementation, bug fixes, refactors, or fleshing out an idea.

    24k GitHub stars~1.2k tokensUpdated today
    DevelopmentAuto-check passed
  • Opsmill Dev Fixing Bugs

    opsmill/infrahub

    Implements and validates the fix for a bug once a failing reproduction test exists.

    529 GitHub stars~3.4k tokensUpdated today
    DevelopmentAuto-check passed
  • Batch Files

    github/awesome-copilot

    Official

    Expert-level Windows batch file (.bat/.cmd) skill for writing, debugging, and maintaining CMD scripts.

    40k GitHub starsUsed in 1 repo~4.3k tokens
    DevelopmentAuto-check passed

More from google-labs-code/stitch-sdk

All 9 skills in this repo
  • Stitch SDK Development

    google-labs-code/stitch-sdk

    Official

    Develop the Stitch SDK. An agent skill from google-labs-code/stitch-sdk.

    1.8k GitHub stars~3.4k tokensUpdated 7 days ago
    Auto-check passed
  • Stitch SDK Domain Design

    google-labs-code/stitch-sdk

    Official

    Design the domain model for the Stitch SDK. An agent skill from google-labs-code/stitch-sdk.

    1.8k GitHub stars~2.4k tokensUpdated 7 days ago
    Auto-check passed
  • Stitch SDK Pipeline

    google-labs-code/stitch-sdk

    Official

    Run the full Stitch SDK generation pipeline. An agent skill from google-labs-code/stitch-sdk.

    1.8k GitHub stars~2k tokensUpdated 7 days ago
    Auto-check passed
  • Stitch SDK Readme

    google-labs-code/stitch-sdk

    Official

    Generate or update the README for the Stitch SDK. An agent skill from google-labs-code/stitch-sdk.

    1.8k GitHub stars~1.8k tokensUpdated 7 days ago
    Auto-check passed
  • Stitch SDK Usage

    google-labs-code/stitch-sdk

    Official

    Use the Stitch SDK to generate, edit, and iterate on UI screens from text prompts, manage projects, and retrieve screen HTML/images.

    1.8k GitHub stars~2.8k tokensUpdated 7 days ago
    Auto-check passed
  • TDD Red Green Refactor

    google-labs-code/stitch-sdk

    Official

    Enforces a disciplined Red-Green-Refactor (TDD) workflow in TypeScript/Node.js.

    1.8k GitHub stars~755 tokensUpdated 7 days ago
    Auto-check passed

Works with

Questions about Stitch SDK Bug Bash

What does Stitch SDK Bug Bash do?

Find bugs in the Stitch SDK using a real API key. An agent skill from google-labs-code/stitch-sdk. Stitch SDK Bug Bash is an agent skill from google-labs-code/stitch-sdk, published by the product's own GitHub organization. Find bugs in the Stitch SDK using a real API key.

When should I use Stitch SDK Bug Bash?

Stitch SDK Bug Bash fits situations like: tasks that involve Debugging.

How do I install Stitch SDK Bug Bash in Claude Code?

Run `npx skills add google-labs-code/stitch-sdk --skill stitch-sdk-bug-bash -a claude-code`. Or copy the skill folder (.agents/skills/stitch-sdk-bug-bash in google-labs-code/stitch-sdk) into .claude/skills/stitch-sdk-bug-bash in your project. Claude Code loads it when a task matches its description.

How do I install Stitch SDK Bug Bash in Codex?

Run `npx skills add google-labs-code/stitch-sdk --skill stitch-sdk-bug-bash -a codex`. Or copy the skill folder (.agents/skills/stitch-sdk-bug-bash in google-labs-code/stitch-sdk) into .agents/skills/stitch-sdk-bug-bash in your project. Codex loads it when a task matches its description.

Can I use Stitch SDK Bug Bash in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add google-labs-code/stitch-sdk --skill stitch-sdk-bug-bash -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/stitch-sdk-bug-bash, .gemini/skills/stitch-sdk-bug-bash, .github/skills/stitch-sdk-bug-bash and .opencode/skills/stitch-sdk-bug-bash in your project.

What does Stitch SDK Bug Bash need to run?

Going by SKILL.md and its folder, Stitch SDK Bug Bash needs credentials named STITCH_API_KEY. Our summary lists: A credential in STITCH_API_KEY.

Does Stitch SDK Bug Bash access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Stitch SDK Bug Bash safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Stitch SDK Bug Bash use?

Stitch SDK Bug Bash is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Stitch SDK Bug Bash use?

About 1.6k tokens (SKILL.md is roughly 6.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Stitch SDK Bug Bash?

Skills that share tags, products or a category with Stitch SDK Bug Bash: Ue Live Debugging (JasonMa0012/MooaToon, 749 stars), Trace And Isolate (rohitg00/skillkit, 1.5k stars), Cpp (crazyguitar/cppcheatsheet, 290 stars) and Code Changes (JanDeDobbeleer/oh-my-posh, 24k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Stitch SDK Bug Bash?

google-labs-code (a GitHub organization, an official publisher) maintains it in google-labs-code/stitch-sdk, which has 1,825 GitHub stars. The repository holds 9 skills in this directory. The repository was last updated on October 1, 2026.

Source: google-labs-code/stitch-sdk on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.