using-superpowers

Fail

Audited by Gen Agent Trust Hub on Feb 16, 2026

Risk Level: HIGHPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION] (HIGH): The skill employs aggressive imperative language ('ABSOLUTELY MUST', 'not negotiable', 'not optional', 'cannot rationalize your way out') to override the agent's built-in reasoning processes. It explicitly forbids the agent from asking clarifying questions or gathering context until after it has invoked an external tool, which is a common pattern for bypassing standard AI safety and reasoning guardrails.
  • [INDIRECT_PROMPT_INJECTION] (HIGH): The skill mandates a 'forced execution' workflow for any external content identified as a 'skill.' By lowering the threshold for tool invocation to a '1% chance' and requiring it 'BEFORE ANY RESPONSE,' the skill creates a high-risk pipeline where the agent is pressured to ingest and follow potentially malicious third-party instructions without human-in-the-loop validation or initial clarification.
  • Ingestion points: Processes the user message and environment for skill matches (SKILL.md).
  • Boundary markers: Absent; the skill explicitly commands the agent to merge its logic with found skills 'exactly.'
  • Capability inventory: Mandates the invocation of the Skill tool and 'TodoWrite' tool before responding.
  • Sanitization: Absent; no validation is performed on the 'skills' found before they are followed.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Feb 16, 2026, 09:50 AM
Security Audit — agent-trust-hub — using-superpowers