using-superpowers
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill employs aggressive, absolute language to override the AI agent's standard decision-making processes and judgment. By stating that tool invocation is "not negotiable" and "not optional," and explicitly instructing the agent that it "cannot rationalize your way out of this," the skill attempts to bypass the agent's internal reasoning and safety guardrails.
- [INDIRECT_PROMPT_INJECTION]: The skill creates a significant vulnerability surface by mandating the ingestion of external data (other skills) based on a extremely low threshold ("1% chance"). This forces the agent to load and potentially follow untrusted instructions from external files before performing its own context gathering or asking clarifying questions.
- Ingestion points: The Skill tool is used to load external file content (skills) into the conversation context.
- Boundary markers: None present; the instructions require following the skills "exactly" and "directly."
- Capability inventory: The agent is instructed to use the Skill tool and TodoWrite.
- Sanitization: No sanitization or validation of the loaded skill content is mentioned.
Audit Metadata