using-superpowers

Warn

Audited by Gen Agent Trust Hub on Aug 9, 2026

Risk Level: MEDIUMPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill employs extremely forceful and absolute language such as "ABSOLUTELY MUST," "not negotiable," "not optional," and "DO NOT HAVE A CHOICE." These are characteristic of prompt injection techniques designed to override the model's core safety guidelines and operational constraints.
  • [PROMPT_INJECTION]: The instructions mandate a "1% rule," requiring the agent to invoke the Skill tool if there is any chance a skill might apply. This deliberately lowers the threshold for tool execution to an unsafe level, potentially leading to the loading of untrusted content.
  • [PROMPT_INJECTION]: The "Red Flags" section specifically instructs the agent to ignore its own logical heuristics and rationalizations (e.g., "I need more context first," "This is just a simple question") in favor of rigid adherence to the skill's commands.
  • [PROMPT_INJECTION]: The skill requires that these actions take place BEFORE any response or action, including clarifying questions. This prevents the agent from seeking user confirmation or context that might identify a malicious tool before it is already loaded into the execution environment.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 9, 2026, 02:16 PM
Security Audit — agent-trust-hub — using-superpowers