claude-superpowers
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill establishes a structured development workflow (Plan, Isolate, Test, Review) that enforces software engineering best practices, which naturally reduces the likelihood of shipping buggy or insecure code.
- [SAFE]: The 'Double Review' stage (Stage 4) specifically mandates a check for security issues, including injection vulnerabilities and exposed secrets, providing an internal layer of defense during the code generation process.
- [SAFE]: No malicious patterns such as prompt injection, data exfiltration, or unauthorized network operations were identified. The workflow operates within the expected context of a software development agent.
- [SAFE]: The persistence mechanism involving
CLAUDE.mdis a standard project-configuration practice for AI coding tools and does not introduce malicious behavior or hidden persistence.
Audit Metadata