using-superpowers

Pass

Audited by Gen Agent Trust Hub on Mar 7, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill uses extremely forceful constraints and imperative language to override the AI's natural decision-making process and behavior.
  • Evidence: The <EXTREMELY-IMPORTANT> block in SKILL.md uses phrases like "ABSOLUTELY MUST," "not negotiable," and "not optional."
  • Evidence: The "Red Flags" section in SKILL.md explicitly tells the agent to disregard its own reasoning ("rationalizations") such as needing more context or exploring the codebase before using a skill.
  • [PROMPT_INJECTION]: The skill mandates a specific tool-use sequence that overrides default agent communication flows, requiring tool invocation before even basic clarifying questions.
  • Evidence: Instructions in SKILL.md state: "Invoke relevant or requested skills BEFORE any response or action. Even a 1% chance a skill might apply means that you should invoke the skill."
  • [COMMAND_EXECUTION]: The documentation provides instructions for the agent to execute shell commands to install and verify the skill on the local system.
  • Evidence: README.md provides git clone and cat commands under the "Claude Code agent install" section.
  • [EXTERNAL_DOWNLOADS]: The skill references a GitHub repository for installation. Since the repository belongs to the skill's author, this is noted as a vendor resource.
  • Evidence: git clone targeting github.com/itsdik/using-superpowers-skill.git in README.md.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 7, 2026, 06:07 PM