superpowers-writing-skills
Warn
Audited by Gen Agent Trust Hub on Mar 15, 2026
Risk Level: MEDIUMPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill documentation in
testing-skills-with-subagents.mdandpersuasion-principles.mdprovides templates for influencing agent behavior using authoritative overrides. It explicitly recommends patterns such asIMPORTANT: This is a real scenario. Choose and act.and absolute imperatives likeYOU MUSTandNo exceptions. These techniques are designed to bypass an agent's standard reasoning process and safety guidelines to ensure compliance under simulated pressure. \n- [COMMAND_EXECUTION]: Therender-graphs.jsutility script useschild_process.execSyncto invoke the systemdotcommand (Graphviz). The script extracts content fromSKILL.mdand pipes it as standard input to the system process. Executing system commands with content derived from user-provided files constitutes a security risk, particularly in environments where input sanitization is not strictly enforced.
Audit Metadata