using-superpowers

Warn

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: MEDIUMPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill uses high-pressure and coercive language to override the agent's default system behavior and autonomy. Evidence includes the use of instructions such as "ABSOLUTELY MUST", "not negotiable", and "not optional" to force adherence to its specific logic. The explicit directive that instructions "override default system behavior" is a behavior manipulation pattern intended to bypass standard operational boundaries.
  • [INDIRECT_PROMPT_INJECTION]: The skill establishes a mandatory workflow that automatically ingests and executes external content based on a low relevance threshold, creating a vulnerability surface for malicious instructions to enter the execution context.
  • Ingestion points: The agent is directed in SKILL.md to search for and invoke external skills using the skill tool based on any user query with a "1% chance" of relevance.
  • Boundary markers: Although the skill notes that user instructions have highest priority, it lacks explicit delimiters or instructions to ignore malicious content within the loaded external files.
  • Capability inventory: The skill requires the invocation of the skill tool and strict adherence to the resulting instructions before the agent can provide a normal response or ask clarifying questions.
  • Sanitization: No mechanisms are provided to validate or sanitize the instructions loaded from the skill tool before they are interpolated into the agent's prompt context.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 13, 2026, 03:49 PM
Security Audit — agent-trust-hub — using-superpowers