using-superpowers

Pass

Audited by Gen Agent Trust Hub on Aug 30, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The instructions use strong imperative language to enforce the use of specialized skills. However, it explicitly states that user instructions take precedence over the skill's rules, maintaining proper control flow and preventing behavior overrides against user intent.
  • [COMMAND_EXECUTION]: The documentation in references/codex-tools.md references standard, read-only git commands for environment detection (e.g., git rev-parse --git-dir). These are used correctly for development workflows and do not exhibit malicious patterns.
  • [SAFE]: The skill serves as a configuration and workflow guide for multi-platform agent behavior. No suspicious data exfiltration, obfuscation, or persistence mechanisms were found.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 30, 2026, 02:56 PM
Security Audit — agent-trust-hub — using-superpowers