using-superpowers
Warn
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: MEDIUMPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill uses high-pressure and coercive language to override the agent's default system behavior and autonomy. Evidence includes the use of instructions such as "ABSOLUTELY MUST", "not negotiable", and "not optional" to force adherence to its specific logic. The explicit directive that instructions "override default system behavior" is a behavior manipulation pattern intended to bypass standard operational boundaries.
- [INDIRECT_PROMPT_INJECTION]: The skill establishes a mandatory workflow that automatically ingests and executes external content based on a low relevance threshold, creating a vulnerability surface for malicious instructions to enter the execution context.
- Ingestion points: The agent is directed in
SKILL.mdto search for and invoke external skills using theskilltool based on any user query with a "1% chance" of relevance. - Boundary markers: Although the skill notes that user instructions have highest priority, it lacks explicit delimiters or instructions to ignore malicious content within the loaded external files.
- Capability inventory: The skill requires the invocation of the
skilltool and strict adherence to the resulting instructions before the agent can provide a normal response or ask clarifying questions. - Sanitization: No mechanisms are provided to validate or sanitize the instructions loaded from the
skilltool before they are interpolated into the agent's prompt context.
Audit Metadata