using-superpowers

Fail

Audited by Socket on Feb 20, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

This document is not itself malware and contains no encoded or obfuscated payloads, but it materially increases supply-chain risk by mandating frequent, unconditional invocation of external skill modules without provenance checks or scope-limiting safeguards. The primary danger is behavioral: more frequent loading of third-party skills widens the attack surface and increases likelihood of sensitive-context exposure or privilege misuse. Recommend treating this policy as high-risk until trust controls, consent, and least-privilege safeguards are added.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 20, 2026, 06:06 AM
Package URL
pkg:socket/skills-sh/Jackiexiao%2Fjackie-skills-cn-top50%2Fusing-superpowers%2F@7837f16da4c3061ca53029ef68ea5ecb5ab3654f