superpowers

Fail

Audited by Socket on Feb 26, 2026

1 alert found:

Malware
MalwareHIGH
using-git-worktrees/SKILL.md

This skill is coherent with its stated purpose: it discovers or asks for a worktrees location, verifies project-local directories are git-ignored (and offers to add and commit .gitignore entries), creates git worktrees, runs project setup, and verifies a clean test baseline. I found no direct malicious code, credential harvesting, remote exfiltration, or download-and-execute from arbitrary URLs. The primary security concern is supply-chain risk inherent in running package manager install/build commands (these execute third-party code and can run arbitrary install/build scripts). Another operational risk is the automation of committing .gitignore entries to the repository without a clearly required explicit user confirmation step — this can modify repo state unexpectedly if an agent acts autonomously. Overall this is functionally appropriate but carries moderate operational/supply-chain risk due to package installs and automated repo commits. Reviewers should ensure interactive confirmation is required before committing changes and consider restricting automatic install/test steps or running them in a sandbox when used by autonomous agents.

Confidence: 85%Severity: 75%
Audit Metadata
Analyzed At
Feb 26, 2026, 01:51 AM
Package URL
pkg:socket/skills-sh/hasmokan%2FThe-Reverse-Turing-Test%2Fsuperpowers%2F@93882cd3b40a86164279c24d748ce9e6d747a0ff