Back to skill

Security audit

Brainstorming

Security checks for vulnerabilities and agentic risk

Overview

This skill is a legitimate brainstorming helper, but it takes unusually broad control over the agent workflow and includes an under-disclosed local web companion that logs interactions and can be exposed on the network.

Review this skill before installing. It may be useful for structured design work, but expect it to slow or override direct implementation requests, write and commit design documents, launch a local browser companion, store mockups and click history, and potentially expose that companion if configured with a non-loopback host. Use it only when you want that workflow, keep the server on localhost, and avoid committing .superpowers/brainstorm artifacts unless intentionally preserved.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:3
Finding

Mandatory Workflow and Skill-Routing Hijack

Content
View full analysis
Do NOT invoke any implementation skill, write any code, scaffold any project, or take any implementation action until you have presented a design and the user has approved it. This applies to EVERY project regardless of perceived simplicity. ## Anti-Pattern: "This Is Too Simple To Need A Design" Every project goes through this process. A todo list, a single-function utility, a config change — all of them. "Simple" projects are where unexamined assumptions cause the most wasted work. The design can be short (a few sentences for truly simple projects), but you MUST present it and get approval. ## Checklist You MUST create a task for each of these items and complete them in order: 1. **Explore project context** — check files, docs, recent commits 2. **Offer visual companion** (if topic will involve visual questions) — this is its own message, not combined with a clarifying question. See the Visual Companion section below. 3. **Ask clarifying questions** — one at a time, understand purpose/constraints/success criteria 4. **Propose 2-3 approaches** — with trade-offs and your recommendation 5. **Present design** — in sections scaled to their complexity, get user approval after each section 6. **Write design doc** — save to `docs/superpowers/specs/YYYY-MM-DD--design.md` and commit 7. **Spec review loop** — dispatch spec-document-reviewer subagent with precisely crafted review context (never your session history); fix issues and re-dispatch until approved (max 3 iteration ...[truncated 2780 chars]
Remediation
View remediation

T07 · Tool Hijacking and Spoofing

Warning
Location
scripts/server.cjs:165
Finding

Unauthenticated WebSocket Event Injection and Source Spoofing

Content
View full analysis
{ buffer = Buffer.concat([buffer, chunk]); while (buffer.length > 0) { let result; try { result = decodeFrame(buffer); } catch (e) { socket.end(encodeFrame(OPCODES.CLOSE, Buffer.alloc(0))); clients.delete(socket); return; } if (!result) break; buffer = buffer.slice(result.bytesConsumed); switch (result.opcode) { case OPCODES.TEXT: handleMessage(result.payload.toString()); break; case OPCODES.CLOSE: socket.end(encodeFrame(OPCODES.CLOSE, Buffer.alloc(0))); clients.delete(socket); return; case OPCODES.PING: socket.write(encodeFrame(OPCODES.PONG, result.payload)); break; case OPCODES.PONG: break; default: { const closeBuf = Buffer.alloc(2); closeBuf.writeUInt16BE(1003); socket.end(encodeFrame(OPCODES.CLOSE, closeBuf)); clients.delete(socket); return; } } } }); socket.on('close', () => clients.delete(socket)); socket.on('error', () => clients.delete(socket)); } function handleMessage(text) { let event; try { event = JSON.parse(text); } catch (e) { console.error('Failed to ...[truncated 3043 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/stop-server.sh:9
Finding

Unvalidated PID Termination and Unsafe Recursive Session Cleanup

Content
View full analysis
"}' exit 1 fi PID_FILE="${SCREEN_DIR}/.server.pid" if [[ -f "$PID_FILE" ]]; then pid=$(cat "$PID_FILE") # Try to stop gracefully, fallback to force if still alive kill "$pid" 2>/dev/null || true # Wait for graceful shutdown (up to ~2s) for i in {1..20}; do if ! kill -0 "$pid" 2>/dev/null; then break fi sleep 0.1 done # If still running, escalate to SIGKILL if kill -0 "$pid" 2>/dev/null; then kill -9 "$pid" 2>/dev/null || true # Give SIGKILL a moment to take effect sleep 0.1 fi if kill -0 "$pid" 2>/dev/null; then echo '{"status": "failed", "error": "process still running"}' exit 1 fi rm -f "$PID_FILE" "${SCREEN_DIR}/.server.log" # Only delete ephemeral /tmp directories if [[ "$SCREEN_DIR" == /tmp/* ]]; then rm -rf "$SCREEN_DIR" fi echo '{"status": "stopped"}' else echo '{"status": "not_running"}' fi ``` ### Technical Analysis The script accepts an arbitrary directory from its caller and derives both the PID file and recursive-deletion target from that value. It does not canonicalize the path or verify that it is a session directory created by `start-server.sh`. The PID file's contents are passed directly to `kill`, including an eventual `SIGKILL`, without checking that the content is a valid positive integer or that the process is the expected `node server.cjs` instance. PID reuse can also cause the script to terminate an unrelated process after the original server exits. The deletion safeguard only checks whether the supplied string begins with `/tmp/`. It does not enforce the expected `/tmp/brainstorm-` naming pattern, validate owners ...[truncated 1334 chars]
Remediation
View remediation
- ``` 3. For persistent sessions, require the expected `.superpowers/brainstorm/` structure and a session marker generated at startup. 4. Reject the target if it or any relevant control file is a symbolic link. 5. Validate PID contents before use: ```bash [[ "$pid" =~ ^[1-9][0-9]*$ ]] || exit 1 ``` 6. Verify that the PID belongs to the expected server process by checking its executable and command line, where supported. 7. Record a random session identifier or process start time in the marker file and verify it before signaling the process. This mitigates PID reuse. 8. Refuse to send `SIGKILL` unless process identity has been positively verified. 9. Replace broad `rm -rf "$SCREEN_DIR"` cleanup with deletion of known session-owned files followed by `rmdir`, or perform recursive deletion only after all path, ownership, and marker checks succeed. 10. Refuse cleanup when executed as root unless an explicit administrative option is provided. ]]>
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
Findings (25)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents this skill as a requirement/design exploration tool to be used before creative work. The supplied code does not implement planning, intent exploration, or design analysis logic. Instead, it functions as a browser-side interaction helper: it connects to a WebSocket server, captures clicks on elements with data-choice, sends those events with timestamps, updates selection indicators in the page, exposes global functions, and reloads the page when instructed by the server. These are materially different capabilities and include undeclared network communication and remote control behavior, so the description does not accurately represent the code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description presents a conceptual planning skill used before creative work, focused on exploring intent and requirements. The supplied code does not implement requirement exploration or design analysis itself; instead, it is operational infrastructure for starting a brainstorm server. Its primary behavior is process management and local server startup, including filesystem writes, PID handling, background execution, and host configuration. These are materially different capabilities from the declared purpose and constitute an undeclared operational/runtime behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says this skill is for exploring intent, requirements, and design prior to implementation. The supplied code does not perform any planning, analysis, or requirements discovery. Its primary purpose is operational: stopping a server process, checking PID liveness, escalating to SIGKILL if needed, removing PID/log files, and deleting temporary directories. These are materially different capabilities and indicate a clear mismatch between the declared purpose and actual behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill description says it 'MUST' be used before any creative work, including very broad categories like features, components, functionality, or behavior changes. That kind of mandatory, expansive trigger can let a non-essential skill intercept a large share of developer interactions, increasing the chance of unnecessary repository access, workflow manipulation, or user-friction without clear need.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
80% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · SKILL.md (reported line 22)May include surrounding context.

md
## Checklist

You MUST create a task for each of these items and complete them in order:

1. **Explore project context** — check files, docs, recent commits
2. **Offer visual companion** (if topic will involve visual questions) — this is its own message, not combined with a clarifying question. See the Visual Companion section below.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill instructs the agent to write a design document to the repository and commit it, but the skill text does not clearly require prior user consent for modifying the working tree or creating commits. In agentic environments, automatic file writes and commits can cause unintended persistence, pollute history, and normalize unauthorized repository changes.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script establishes a persistent WebSocket connection to the current host and uses it for event delivery and remote commands, which goes beyond a brainstorming skill's stated purpose of intent exploration. This expands the attack surface by enabling live telemetry and command-driven behavior in the browser without clear necessity, making misuse or compromise of the hosting endpoint materially more dangerous.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The WebSocket message handler accepts a server-supplied "reload" command and immediately reloads the page, giving the remote endpoint direct control over client page state. Even if limited to reload today, this is an unjustified remote control primitive for a brainstorming skill and could be abused for disruption, coercing repeated reconnects, or enabling future expansion into more dangerous commands.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The code captures user clicks on elements marked with data-choice and sends text content, choice values, IDs, and timestamps over a WebSocket without any visible notice or consent mechanism. In this skill context, that creates undisclosed behavioral telemetry that can reveal user decisions and interaction patterns beyond what is necessary for simple brainstorming assistance.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This file implements a full local HTTP and WebSocket server, serves dynamic HTML from disk, watches a directory, and persists server state. That is materially broader capability than a brainstorming-only skill requires, increasing attack surface and enabling user interaction capture and local content serving that could be abused if untrusted HTML is placed in the watched directory.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The server accepts arbitrary WebSocket messages from connected clients, logs them, and persists events containing user choices to a hidden file in the screen directory. For a brainstorming skill, collecting and storing browser interaction telemetry is not clearly necessary and creates an unnecessary privacy and integrity risk, especially because there is no authentication or disclosure in this code.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

User interaction data is appended to a hidden on-disk .events file without any visible notice, consent, retention policy, or access control handling in this file. Persisting potentially sensitive selections to disk can expose private user intent or behavior to other local processes or later recovery from temporary storage.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/start-server.sh (reported line 67)May include surrounding context.

sh
FOREGROUND="true"
fi

# Windows/Git Bash reaps nohup background processes. Auto-foreground when detected.
if [[ "$FOREGROUND" != "true" && "$FORCE_BACKGROUND" != "true" ]]; then
  case "${OSTYPE:-}" in
    msys*|cygwin*|mingw*) FOREGROUND="true" ;;

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/start-server.sh (reported line 124)May include surrounding context.

sh
FOREGROUND="true"
fi

# Windows/Git Bash reaps nohup background processes. Auto-foreground when detected.
if [[ "$FOREGROUND" != "true" && "$FORCE_BACKGROUND" != "true" ]]; then
  case "${OSTYPE:-}" in
    msys*|cygwin*|mingw*) FOREGROUND="true" ;;

Session Persistence

Medium
Category
Rogue Agent
Confidence
83% confidence
Finding

This finding corresponds to the use of disown together with nohup on the same launch path, which removes the server from the shell job table and makes it harder for the invoking environment to track and clean up. In a skill that launches a brainstorming server, that persistence is functional rather than obviously malicious, but it still weakens operator control and can leave unintended services running.

Content

Scanner excerpt · scripts/start-server.sh (reported line 123)May include surrounding context.

sh
fi

# Start server, capturing output to log file
# Use nohup to survive shell exit; disown to remove from job table
nohup env BRAINSTORM_DIR="$SCREEN_DIR" BRAINSTORM_HOST="$BIND_HOST" BRAINSTORM_URL_HOST="$URL_HOST" BRAINSTORM_OWNER_PID="$OWNER_PID" node server.cjs > "$LOG_FILE" 2>&1 &
SERVER_PID=$!
disown "$SERVER_PID" 2>/dev/null

Session Persistence

Medium
Category
Rogue Agent
Confidence
83% confidence
Finding

This finding corresponds to the use of disown together with nohup on the same launch path, which removes the server from the shell job table and makes it harder for the invoking environment to track and clean up. In a skill that launches a brainstorming server, that persistence is functional rather than obviously malicious, but it still weakens operator control and can leave unintended services running.

Content

Scanner excerpt · scripts/start-server.sh (reported line 123)May include surrounding context.

sh
fi

# Start server, capturing output to log file
# Use nohup to survive shell exit; disown to remove from job table
nohup env BRAINSTORM_DIR="$SCREEN_DIR" BRAINSTORM_HOST="$BIND_HOST" BRAINSTORM_URL_HOST="$URL_HOST" BRAINSTORM_OWNER_PID="$OWNER_PID" node server.cjs > "$LOG_FILE" 2>&1 &
SERVER_PID=$!
disown "$SERVER_PID" 2>/dev/null

Session Persistence

Medium
Category
Rogue Agent
Confidence
65% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · scripts/start-server.sh (reported line 126)May include surrounding context.

sh
# Use nohup to survive shell exit; disown to remove from job table
nohup env BRAINSTORM_DIR="$SCREEN_DIR" BRAINSTORM_HOST="$BIND_HOST" BRAINSTORM_URL_HOST="$URL_HOST" BRAINSTORM_OWNER_PID="$OWNER_PID" node server.cjs > "$LOG_FILE" 2>&1 &
SERVER_PID=$!
disown "$SERVER_PID" 2>/dev/null
echo "$SERVER_PID" > "$PID_FILE"

# Wait for server-started message (check log file)

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The script reads a PID from a file inside a user-supplied directory and sends SIGTERM and then SIGKILL to that PID without validating that the process is actually the brainstorm server started by this skill. If an attacker can control the pid file or SCREEN_DIR, they can terminate arbitrary processes accessible to the script's privileges, which is a powerful and unrelated capability for a brainstorming skill.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script recursively deletes whatever directory is passed in as SCREEN_DIR as long as it begins with /tmp, without verifying that it is a directory created by this skill or otherwise owned/expected. An attacker who can influence the argument could cause deletion of arbitrary /tmp contents, exceeding the narrow stop/cleanup purpose and creating a destructive filesystem capability.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The manifest describes a skill focused on exploring user intent, requirements, and design before implementation. This file operationalizes that by having the agent launch infrastructure, generate browser-served HTML artifacts, and store session data under the project directory, which is materially more than lightweight brainstorming guidance.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

A brainstorming skill can reasonably help structure ideas and design options, but instructing the agent to launch and manage a persistent HTTP server is a distinct operational capability. That capability is not clearly justified by the manifest's narrow purpose of exploring intent, requirements, and design before implementation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The workflow collects browser interaction data in .events and persists mockup files, but the guide does not instruct the operator to notify the user that their clicks and visual choices are being logged. Even if the data is low sensitivity in many cases, it may still reveal preferences, internal product ideas, or sensitive UI concepts without informed consent.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The guide explicitly encourages persisting mockups and interaction artifacts under the project directory, which can unintentionally retain sensitive design content and user interaction history inside a workspace that may later be committed, synced, or shared. For a brainstorming aid, storing these artifacts in the main project path broadens data retention beyond what is necessary for the task.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guide recommends binding the server to 0.0.0.0 when localhost is unreachable, but it does not warn that this exposes the mockup server to other machines on the network and potentially to broader attack surfaces depending on host networking. Because the content can include project-specific mockups and interaction logging, accidental network exposure could leak sensitive internal information or allow unauthorized access.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The text notes that mockups persist in .superpowers/brainstorm/ and merely reminds the user to add .superpowers/ to .gitignore, but it does not clearly warn that these files may contain sensitive design drafts, internal architecture, or user-driven selections. That creates a retention and accidental disclosure risk if the directory is committed or shared.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.