using-superpowers

Warn

Audited by Socket on Feb 26, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The file contains no embedded malware or hardcoded secrets, but it defines an unsafe operational policy: mandatory, preemptive invocation of external skills based on a permissive '1% applies' heuristic and a prohibition on delaying invocation for clarifying questions or consent. That policy substantially increases supply-chain and data-exfiltration risks by causing frequent, unvetted fetching and execution of third-party skill content and by removing ordinary human-in-the-loop or verification steps. Recommended mitigations before adopting this policy: require signed/pinned skill sources, enforce allowlists and domain restrictions, require per-invocation human confirmation before sharing secrets or executing commands, log and audit all fetched skill content and actions, and limit the heuristic (do not use a 1% threshold). Treat the policy as suspicious and high-risk until such controls are in place.

Confidence: 75%Severity: 75%
Audit Metadata
Analyzed At
Feb 26, 2026, 10:15 PM
Package URL
pkg:socket/skills-sh/PracticalSwan%2Fagent-skills%2Fusing-superpowers%2F@2a7f5982368c25f5352a5be2d10ad9a753334226