using-superpowers

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • NO_CODE (SAFE): The skill consists strictly of instructional Markdown documentation and contains no executable code, scripts, or binaries.\n- SAFE (SAFE): A review of all threat categories identified no malicious patterns, obfuscation, or exfiltration attempts.\n- PROMPT_INJECTION (SAFE): The skill directs the agent to check other skills in the local directory, which is a standard workflow practice rather than a malicious instruction bypass.\n
  • Ingestion points: Local file system path .agent/skills/.\n
  • Boundary markers: Absent (instructions rely on agent's default handling of skills).\n
  • Capability inventory: None; the skill is documentation-only and does not possess internal capabilities to write files or execute commands.\n
  • Sanitization: None provided in the documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 06:35 PM