using-superpowers

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill employs high-pressure and imperative language in the <EXTREMELY-IMPORTANT> section, such as "ABSOLUTELY MUST," "NOT NEGOTIABLE," and "You cannot rationalize your way out of this." These instructions are designed to override the agent's internal autonomy and decision-making logic regarding when a skill should be invoked.
  • [PROMPT_INJECTION]: The Red Flags section provides a lookup table to intercept the agent's logical reasoning (e.g., "I need more context first") and replace it with a mandated action ("Skill check comes BEFORE clarifying questions"), effectively creating a behavioral constraint that prevents standard agent operations until the skill is executed.
  • [COMMAND_EXECUTION]: The file references/codex-tools.md provides shell commands for environment detection (git rev-parse --git-dir and git branch --show-current). While these are standard utility commands for developers, they represent a surface area for host-level command execution within the skill's reference materials.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 06:18 AM
Security Audit — agent-trust-hub — using-superpowers