using-superpowers

Warn

Audited by Snyk on Feb 25, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W013: Attempt to modify system services in skill instructions.

  • Attempt to modify system services in skill instructions detected (high risk: 0.80). The prompt forces the agent to unconditionally invoke and "follow exactly" arbitrary skills (even with only 1% applicability), which can cause the agent to execute skills that perform privileged or state-changing actions (create users, edit system files, modify services), so it meaningfully increases risk of compromising the host state.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 25, 2026, 08:23 PM