skills/nshipster/sosumi.ai/sosumi/Gen Agent Trust Hub

sosumi

Pass

Audited by Gen Agent Trust Hub on May 12, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions for users to download the @nshipster/sosumi CLI package from the official NPM registry and the SKILL.md file from the project's own domain, sosumi.ai.
  • [COMMAND_EXECUTION]: Documentation includes instructions for users to run standard installation and execution commands using package managers (npm, bun, deno) and the npx utility for interacting with the service.
  • [DATA_EXFILTRATION]: Documentation requests are directed from developer.apple.com to sosumi.ai. This is the core design feature of the service to facilitate AI-readable documentation rendering.
  • [SAFE]: Zero-width spaces (​) are used in the index.html file to assist with text wrapping of long URLs in the UI, which is a benign layout practice. A Cursor deep link contains a base64-encoded configuration string for server setup.
  • [PROMPT_INJECTION]: The skill has an indirect ingestion surface as it processes external documentation content.
  • Ingestion points: fetchExternalDocumentation and fetchAppleDocumentation tools.
  • Boundary markers: Not specified in the instructions.
  • Capability inventory: The skill is a data provider and lacks capabilities for local file system writes or subprocess execution beyond the documented search/fetch operations.
  • Sanitization: Not explicitly defined within the skill instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
May 12, 2026, 08:03 AM