using-superpowers
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill uses extremely aggressive imperative language ("ABSOLUTELY MUST", "non-negotiable", "not optional") to force specific tool usage and override the agent's normal evaluation of task relevance.
- [PROMPT_INJECTION]: A 'Red Flags' section is included to explicitly instruct the agent to suppress its own logical reasoning (referred to as "rationalizing") that might otherwise lead it to skip a tool invocation.
- [INDIRECT_PROMPT_INJECTION]: The skill mandates a workflow that increases the attack surface for indirect injections by requiring the agent to load external content based on a "1% chance" of relevance, without providing boundary markers or sanitization logic.
- Ingestion points: The
Skilltool mentioned in SKILL.md is used to load and execute content from external files into the active session. - Boundary markers: None provided; the agent is told to "follow it directly" and "follow skill exactly."
- Capability inventory: Includes the
Skilltool (content loading) andTodoWritetool (writing tasks). - Sanitization: The skill lacks any instructions for filtering, validating, or escaping the content loaded from external skills.
Audit Metadata