Back to skill

Security audit

Superpower with Files

Security checks across malware telemetry and agentic risk

Overview

This appears to be a legitimate coding workflow skill, but it can automatically run hook scripts and read prior AI session logs, so it should be reviewed before enabling.

Install only if you are comfortable with persistent project memory files, possible reading of prior local AI session history, and automatic hook scripts. Before enabling it, inspect the installed hook paths, consider disabling session-catchup if not needed, avoid putting secrets in chat or planning files, and manually approve git/PR/destructive operations.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

Detected: suspicious.dangerous_exec

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
skills/writing-skills/render-graphs.js:25