using-superpowers

Pass

Audited by Gen Agent Trust Hub on Jun 23, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill uses coercive and imperative language intended to override the agent's default decision-making logic. Examples include 'ABSOLUTELY MUST invoke', 'This is not negotiable', 'This is not optional', and 'You cannot rationalize your way out of this'. These patterns are typical of behavioral-override prompt injections.
  • [PROMPT_INJECTION]: The skill explicitly instructs the agent that 'Superpowers skills override default system prompt behavior', attempting to alter the core instruction hierarchy of the AI model.
  • [COMMAND_EXECUTION]: The tool mapping files (references/gemini-tools.md, references/copilot-tools.md, and references/codex-tools.md) describe the use of powerful system tools including shell command execution (run_shell_command, bash), file modifications (write_file, replace, edit), and subagent dispatching (spawn_agent, task). While these are standard capabilities for the targeted developer tools, they represent high-privilege operations.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 23, 2026, 12:11 AM
Security Audit — agent-trust-hub — using-superpowers