sumi-orchestrator
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill functions as a high-level router and orchestrator for specialized UX/UI design skills. The instructions are focused on task sequencing and artifact management within the project's local context, such as the .sumi directory. No unauthorized network operations, credential harvesting, or suspicious code execution patterns were detected.
- [PROMPT_INJECTION]: The skill demonstrates a surface for indirect prompt injection due to its core purpose of auditing and fixing user-provided UI/UX content. Ingestion points: External UI code, layout blocks, and design specifications provided by users during the Evaluate and Fix pipeline stages. Boundary markers: The skill does not define explicit delimiters or instructions to ignore embedded commands within analyzed content. Capability inventory: The skill manages a broad range of 43 skills and 37 commands, including MCP tool interactions for design generation. Sanitization: There is no evidence of specific input sanitization or filtering for the external data being processed. The risk is mitigated by the skill's inclusion of specific audit stages for detecting dark patterns and ethics violations.
Audit Metadata