using-superpowers

Pass

Audited by Gen Agent Trust Hub on Apr 24, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill uses forceful imperative language such as 'YOU DO NOT HAVE A CHOICE' and 'not negotiable' to ensure the agent checks for relevant skills before responding. While this employs 'system-level' override patterns, it is mitigated by an explicit priority system that places 'User's explicit instructions' at the highest priority.
  • [COMMAND_EXECUTION]: Includes read-only shell command examples (e.g., 'git rev-parse', 'git branch --show-current') intended for environment detection in development workflows. These are benign and used to adapt the skill's behavior to the local environment.
  • [DATA_EXFILTRATION]: Documents tool mappings for network-capable tools like 'WebFetch' and 'WebSearch' to assist in cross-platform portability. No logic for unauthorized data transmission or exfiltration is present.
  • [SAFE]: The repository provides documentation and tool mappings to maintain consistency across different AI agent environments without introducing malicious code, obfuscated logic, or unauthorized privilege escalation.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 24, 2026, 10:13 AM
Security Audit — agent-trust-hub — using-superpowers