using-superpowers

Fail

Audited by Socket on Feb 27, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

This document is a procedural/workflow policy that enforces unconditional invocation of external 'skills' whenever there is any chance they apply. It does not itself perform network I/O or contain malware-like code, but it substantially increases supply-chain and operational risk by compelling frequent, low-threshold loading and execution of third-party skill code while forbidding safer review mechanisms. Treat this policy as high-risk operational guidance: require vetting, explicit permission, sandboxing, and the ability to review skill content prior to execution to mitigate credential theft, data exfiltration, and other side effects.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 27, 2026, 06:57 PM
Package URL
pkg:socket/skills-sh/futuregerald%2Ffuturegerald-claude-plugin%2Fusing-superpowers%2F@127b35f6aa1b498d40b2d9c71a09b0a564c96c6b