using-superpowers

Fail

Audited by Socket on Feb 14, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

This file is not directly malicious but is high-risk as a policy: it compels the agent to automatically discover and execute other skills and to transmit checklist items via TodoWrite, which can enable supply-chain attacks and data leakage unless strict controls are added. Recommendations: restrict skill sources to verified/trusted repositories, require explicit user consent before executing skills that request sensitive permissions, implement capability-scoped permission checks, ensure TodoWrite targets are trusted or local, and add audit/logging and an allowlist/denylist for skills. Treat this policy with caution in production.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 14, 2026, 04:48 PM
Package URL
pkg:socket/skills-sh/enuno%2Fclaude-command-and-control%2Fusing-superpowers%2F@78034860aa7d464a3d180eed09306abcf5795e03