Back to skill

Security audit

Superpowers Cn

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed Chinese coding-workflow skill that guides clarification, planning, execution, and review without hidden access, persistence, or data exfiltration behavior.

Install this only if you want a Chinese-language workflow that may activate for common coding requests and encourage clarification before implementation. Users who prefer another language or a narrower opt-in trigger may want the skill adjusted before use.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (8)

Vague Triggers

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

The trigger phrases are very broad, generic terms such as '开发', '写代码', and '帮我做', which can overlap with ordinary user requests and cause the skill to activate unintentionally. Unintended activation can alter agent behavior by forcing this workflow onto unrelated tasks, reducing predictability and creating an avenue for prompt-routing mistakes or policy bypass through overly aggressive skill selection.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The description says this is a framework '专为中文AI助手设计' and later emphasizes Chinese as the skill language. This is a natural-language locale restriction presented as a default requirement rather than an optional language mode, which can conflict with language-choice policy.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill is explicitly positioned as a Chinese-language workflow framework without offering language choice or confirming user preference. While not a direct exploit primitive, this can cause unintended application to users who did not opt into Chinese output, increasing confusion, misexecution risk, and the chance that important clarifications or safety-relevant details are misunderstood.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file’s natural-language strings and branding explicitly target 'CN' and present the workflow entirely in Chinese, without offering any language or locale choice. Per the policy, forcing a specific language is a violation unless the locale constraint is clearly documented and justified or made opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Comments and all user-facing question strings are written in Chinese, and the generated clarification prompt also assumes Chinese responses. This can violate language/locale policy when a skill forces a specific language without user opt-in and does not state that it is intentionally limited to a Chinese-language context.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The file’s natural-language documentation is entirely in Chinese and labels the skill as "CN," while all user-facing log messages are also Chinese. This imposes a specific language/locale without any opt-in, fallback, or explanation that the skill is intended only for a Chinese-language environment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The file header explicitly labels the skill as "超能力 CN", indicating a Chinese-language variant or requirement. This is a natural-language locale constraint, but the file provides no user choice or opt-in for language, which can violate language/locale policy expectations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The header and surrounding natural-language comments indicate this skill is specifically framed as "CN" and all user-facing checklist/report content is hardcoded in Chinese. This constitutes a language/locale restriction with no evidence of user choice, opt-in, or a documented region-specific justification.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.