using-superpowers
Warn
Audited by Gen Agent Trust Hub on Aug 9, 2026
Risk Level: MEDIUMPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill employs extremely forceful and absolute language such as "ABSOLUTELY MUST," "not negotiable," "not optional," and "DO NOT HAVE A CHOICE." These are characteristic of prompt injection techniques designed to override the model's core safety guidelines and operational constraints.
- [PROMPT_INJECTION]: The instructions mandate a "1% rule," requiring the agent to invoke the Skill tool if there is any chance a skill might apply. This deliberately lowers the threshold for tool execution to an unsafe level, potentially leading to the loading of untrusted content.
- [PROMPT_INJECTION]: The "Red Flags" section specifically instructs the agent to ignore its own logical heuristics and rationalizations (e.g., "I need more context first," "This is just a simple question") in favor of rigid adherence to the skill's commands.
- [PROMPT_INJECTION]: The skill requires that these actions take place BEFORE any response or action, including clarifying questions. This prevents the agent from seeking user confirmation or context that might identify a malicious tool before it is already loaded into the execution environment.
Audit Metadata