using-superpowers

Warn

Audited by Snyk on Feb 24, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W013: Attempt to modify system services in skill instructions.

  • Attempt to modify system services in skill instructions detected (low risk: 0.30). The prompt itself does not instruct the agent to obtain sudo, edit system files, or create users, but it mandates reading and executing arbitrary skill files (which could themselves perform privileged or state-changing actions), so it poses an indirect risk to machine state.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 24, 2026, 02:49 PM