obra-superpowers-pack

Warn

Audited by Socket on Mar 26, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the manifest is coherent as a bundle of obra/superpowers skills, but its core behavior is transitive installation of many external skills through a third-party CLI and mutable GitHub paths. No direct credential theft or exfiltration is shown here, yet the delegated trust footprint is broader than a simple local helper and warrants medium-high security caution.

Confidence: 87%Severity: 74%
Audit Metadata
Analyzed At
Mar 26, 2026, 03:12 AM
Package URL
pkg:socket/skills-sh/Peiiii%2Fskild%2Fobra-superpowers-pack%2F@3ad2f285467161e288135c9efc3cb6f82a2e2f3d
Security Audit — socket — obra-superpowers-pack