using-superpowers

Pass

Audited by Gen Agent Trust Hub on Mar 26, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's primary purpose is to define a meta-workflow for tool invocation across different agent platforms (Claude Code, Codex, and Gemini CLI). It contains no executable code or sensitive operations.
  • [PROMPT_INJECTION]: The skill employs highly assertive language ("ABSOLUTELY MUST", "non-negotiable", "cannot rationalize your way out") to override default model behavior regarding tool usage. However, it explicitly includes a self-correcting hierarchy where user instructions (e.g., CLAUDE.md, direct requests) are granted the highest priority, preventing it from being used to bypass user intent.
  • [COMMAND_EXECUTION]: The reference files (references/codex-tools.md and references/gemini-tools.md) provide mappings for standard platform tools like Bash and run_shell_command. These are documented for compatibility purposes and are not invoked by the skill itself.
  • [NO_CODE]: The skill consists entirely of instructional markdown and configuration references, with no scripts, package dependencies, or external downloads.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 26, 2026, 07:36 AM