using-superpowers
Warn
Audited by Socket on Apr 14, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS. The skill’s stated purpose is process guidance, but its actual effect is to compel broad, pre-response loading of additional skill instructions, increasing indirect prompt-injection and workflow-control risk. It does not show credential theft, exfiltration, or malicious payload delivery, so this is not confirmed malware.
Confidence: 85%Severity: 56%
Audit Metadata