using-superpowers

Warn

Audited by Gen Agent Trust Hub on May 7, 2026

Risk Level: MEDIUMPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The instructions in SKILL.md use highly assertive language (e.g., 'ABSOLUTELY MUST', 'not negotiable', 'not optional') to compel the agent to follow specific workflows and remove its reasoning discretion.
  • [PROMPT_INJECTION]: The skill explicitly directs the agent that 'Superpowers skills override default system behavior,' a common pattern used to bypass system-level constraints and safety guidelines.
  • [PROMPT_INJECTION]: It enforces a '1% rule' for tool invocation, which forces the agent to execute tools even when they might not be relevant, potentially facilitating the execution of malicious instructions from other skills without sufficient validation.
Audit Metadata
Risk Level
MEDIUM
Analyzed
May 7, 2026, 01:27 AM