using-superpowers

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill uses extremely aggressive imperative language ("ABSOLUTELY MUST", "non-negotiable", "not optional") to force specific tool usage and override the agent's normal evaluation of task relevance.
  • [PROMPT_INJECTION]: A 'Red Flags' section is included to explicitly instruct the agent to suppress its own logical reasoning (referred to as "rationalizing") that might otherwise lead it to skip a tool invocation.
  • [INDIRECT_PROMPT_INJECTION]: The skill mandates a workflow that increases the attack surface for indirect injections by requiring the agent to load external content based on a "1% chance" of relevance, without providing boundary markers or sanitization logic.
  • Ingestion points: The Skill tool mentioned in SKILL.md is used to load and execute content from external files into the active session.
  • Boundary markers: None provided; the agent is told to "follow it directly" and "follow skill exactly."
  • Capability inventory: Includes the Skill tool (content loading) and TodoWrite tool (writing tasks).
  • Sanitization: The skill lacks any instructions for filtering, validating, or escaping the content loaded from external skills.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 02:33 PM
Security Audit — agent-trust-hub — using-superpowers