using-superpowers
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill employs high-pressure and imperative language in the
<EXTREMELY-IMPORTANT>section, such as "ABSOLUTELY MUST," "NOT NEGOTIABLE," and "You cannot rationalize your way out of this." These instructions are designed to override the agent's internal autonomy and decision-making logic regarding when a skill should be invoked. - [PROMPT_INJECTION]: The
Red Flagssection provides a lookup table to intercept the agent's logical reasoning (e.g., "I need more context first") and replace it with a mandated action ("Skill check comes BEFORE clarifying questions"), effectively creating a behavioral constraint that prevents standard agent operations until the skill is executed. - [COMMAND_EXECUTION]: The file
references/codex-tools.mdprovides shell commands for environment detection (git rev-parse --git-dirandgit branch --show-current). While these are standard utility commands for developers, they represent a surface area for host-level command execution within the skill's reference materials.
Audit Metadata