using-superpowers

Fail

Audited by Socket on Feb 15, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The file is a high-risk policy enabler rather than direct malware. It should be treated as suspicious in open or untrusted deployments because it mandates blind invocation and execution of external skill content while forbidding alternate inspection. Mitigations before use: require cryptographic provenance (signed skills), enforce allowlists and capability-scoped sandboxes for skills, add human-in-the-loop approval for high-impact actions, and permit independent review (allow Read tool). Without such controls, this policy significantly raises the chance of supply-chain and social-engineering compromise.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 15, 2026, 07:46 PM
Package URL
pkg:socket/skills-sh/obra%2Fsuperpowers%2Fusing-superpowers%2F@2a7f5982368c25f5352a5be2d10ad9a753334226