using-superpowers

Warn

Audited by Snyk on Feb 27, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W013: Attempt to modify system services in skill instructions.

  • Attempt to modify system services in skill instructions detected (high risk: 0.80). The prompt itself doesn't instruct sudo or file/user changes, but it forcibly requires invoking and following other skills unconditionally—effectively delegating control and enabling downstream skills to perform privileged actions (create users, edit system/ssh/systemd files), so it presents a high risk of compromising machine state.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 27, 2026, 08:34 AM