using-superpowers

Fail

Audited by Snyk on Mar 7, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 0.90). The content contains no explicit exfiltration or remote‑execution code, but it intentionally forces blind, mandatory invocation of external "skills" while instructing agents not to inspect skill files — a clear enabling pattern for supply‑chain backdoors, covert data exfiltration or remote command execution via malicious skills and social‑engineering of the agent.
Audit Metadata
Risk Level
CRITICAL
Analyzed
Mar 7, 2026, 06:07 PM