using-superpowers

Warn

Audited by Gen Agent Trust Hub on Jun 26, 2026

Risk Level: MEDIUMPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains explicit instructions to override the agent's default instructions. It states that "Superpowers skills override default system prompt behavior" and explicitly ranks the "Default system prompt" as the "lowest priority". This constitutes a system prompt override attempt.
  • [PROMPT_INJECTION]: The instructions utilize mandatory and forceful language ("YOU ABSOLUTELY MUST", "IF A SKILL APPLIES... YOU DO NOT HAVE A CHOICE") to compel the agent to use specific tools regardless of its own reasoning or standard safety protocols regarding tool execution.
  • [PROMPT_INJECTION]: The skill defines an indirect prompt injection surface by requiring the agent to invoke tools (the "Skill" or "activate_skill" tools) based on a very low threshold of relevance ("1% chance"). This behavior can be exploited to force the agent to load and execute content from other files or skills that might contain malicious instructions.
  • Ingestion points: Ingests user instructions and codebase context (filenames, skill names) in "SKILL.md" to trigger skill tool calls.
  • Boundary markers: Absent. There are no instructions to differentiate between user-provided data and authoritative skill identifiers.
  • Capability inventory: Includes the ability to activate skills, run shell commands ("Bash"), and spawn subagents ("Task") as referenced in "references/codex-tools.md", "references/copilot-tools.md", and "references/gemini-tools.md".
  • Sanitization: Absent. The skill does not instruct the agent to validate the source or content of a skill before invoking it.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 26, 2026, 05:35 PM
Security Audit — agent-trust-hub — using-superpowers