using-superpowers
Fail
Audited by Gen Agent Trust Hub on Feb 16, 2026
Risk Level: HIGHPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION] (HIGH): The skill employs aggressive imperative language ('ABSOLUTELY MUST', 'not negotiable', 'not optional', 'cannot rationalize your way out') to override the agent's built-in reasoning processes. It explicitly forbids the agent from asking clarifying questions or gathering context until after it has invoked an external tool, which is a common pattern for bypassing standard AI safety and reasoning guardrails.
- [INDIRECT_PROMPT_INJECTION] (HIGH): The skill mandates a 'forced execution' workflow for any external content identified as a 'skill.' By lowering the threshold for tool invocation to a '1% chance' and requiring it 'BEFORE ANY RESPONSE,' the skill creates a high-risk pipeline where the agent is pressured to ingest and follow potentially malicious third-party instructions without human-in-the-loop validation or initial clarification.
- Ingestion points: Processes the user message and environment for skill matches (SKILL.md).
- Boundary markers: Absent; the skill explicitly commands the agent to merge its logic with found skills 'exactly.'
- Capability inventory: Mandates the invocation of the Skill tool and 'TodoWrite' tool before responding.
- Sanitization: Absent; no validation is performed on the 'skills' found before they are followed.
Recommendations
- AI detected serious security threats
Audit Metadata