using-superpowers
Warn
Audited by Socket on Apr 12, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill is not overtly malicious and has no direct credential or network exfiltration behavior, but it disproportionately forces transitive trust in any installed skill before every response. Its main risk is workflow hijacking and exposure to downstream skills of unknown provenance or safety.
Confidence: 84%Severity: 55%
Audit Metadata