using-superpowers

Pass

Audited by Gen Agent Trust Hub on May 7, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill contains instructions that prioritize its own operational framework over the default system prompt behavior. However, it explicitly states that user-provided instructions (e.g., CLAUDE.md or direct requests) always take the highest priority, which prevents the framework from bypassing user control.
  • [COMMAND_EXECUTION]: The reference files include shell command snippets for environment detection, such as identifying git directories and branch names. These commands are used for session context awareness and do not demonstrate unauthorized execution or malicious intent.
  • [SAFE]: No external downloads, hardcoded credentials, or data exfiltration mechanisms were identified. The tool mappings provided for Codex, Copilot, and Gemini platforms are standard operational configurations for those environments.
Audit Metadata
Risk Level
SAFE
Analyzed
May 7, 2026, 05:25 PM