using-superpowers

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFE
Full Analysis
  • [Instructional Hierarchy and User Priority]: The skill establishes a robust priority system (defined in SKILL.md) where user-provided instructions always take precedence over the skill's own rules and the default system prompt. This architectural choice ensures the agent remains under user control and mitigates the risk of behavioral overrides.
  • [Cross-Platform Tool Mapping]: The reference files (e.g., gemini-tools.md, copilot-tools.md) provide static mappings between various platform-specific tools. This serves as an operational configuration for portability and does not introduce security vulnerabilities or unexpected capabilities.
  • [Environment Detection Logic]: The skill includes non-destructive, read-only shell commands for environment detection, such as using git to identify the current branch or worktree status. These commands are standard for development workflows and do not involve privilege escalation or data exfiltration.
  • [Workflow Enforcement]: While the skill uses strong imperative language to ensure the agent checks for relevant skills before responding, this is intended for procedural consistency within the vendor's ecosystem and does not attempt to bypass safety filters or platform constraints.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 10:51 AM
Security Audit — agent-trust-hub — using-superpowers