using-superpowers

Pass

Audited by Gen Agent Trust Hub on Jul 24, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill uses authoritative language (e.g., 'ABSOLUTELY MUST', 'not negotiable') to define its own execution priority over default agent behaviors. This is intended to enforce a structured workflow and includes instructions for subagents to skip the skill if it does not apply to their specific task. It also provides a 'Red Flags' section to prevent the agent from deviating from established processes.\n- [COMMAND_EXECUTION]: Reference files (such as references/gemini-tools.md and references/claude-code-tools.md) map generic skill actions like 'Run a shell command' to platform-specific tools such as run_shell_command or Bash. These mappings are documented to ensure compatibility and do not contain immediate executable code or unauthorized shell access.\n- [EXTERNAL_DOWNLOADS]: The documentation mentions platform tools for fetching URLs (e.g., web_fetch, WebFetch) and searching the web. These are descriptions of built-in agent capabilities used by implementation skills and do not represent a security risk within the context of this coordination skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 24, 2026, 05:32 PM
Security Audit — agent-trust-hub — using-superpowers