meta-superpowers

Fail

Audited by Socket on Mar 1, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The meta-superpowers document is a high-risk orchestration policy rather than direct malware. Its mandatory, unconditional requirement to discover and execute other skills (including 'load the latest file') creates significant supply-chain, prompt-injection, and autonomy-abuse risks. If deployed without strong controls (provenance verification, per-skill consent, sandboxing, least-privilege secrets access, and allowlisting), it materially increases the chance that malicious or compromised skills will execute arbitrary code, exfiltrate data, or misuse credentials. Recommended remediation: require origin verification and signatures for skills, implement explicit user consent and per-skill permission prompts, sandbox skill execution, and apply least-privilege access to secrets and network resources.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 1, 2026, 01:12 AM
Package URL
pkg:socket/skills-sh/tjboudreaux%2Fcc-plugin-engineering-excellence%2Fmeta-superpowers%2F@04c88b366b9da7696b11dd0a2c73d76ae320a477