using-superpowers

Fail

Audited by Socket on Feb 17, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The manifest is not itself malware and contains no direct network calls or hard-coded secrets. However, it materially increases supply-chain and operational risk by requiring the agent to invoke external skill code whenever there is even a minimal chance a skill might apply, with no stated permission model, least-privilege constraints, or data-sensitivity protections. That forced behavior expands the attack surface and makes credential harvesting or data exfiltration by third-party skills more likely if such skills are malicious or insufficiently audited. Recommend adding explicit guards: user consent prompts for sensitive data, scoped permissions for skills, vetting/code-signing of skills, sandboxing, logging/auditing of skill invocations, and clear rules prohibiting forwarding of secrets to skills.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 17, 2026, 05:53 PM
Package URL
pkg:socket/skills-sh/hjewkes%2Fagent-skills%2Fusing-superpowers%2F@f77a655ea175dec2b4c05ea96cc0b19ac7724b2c