Super Dev Pipeline

PassAudited by VirusTotal on Apr 1, 2026.

Findings (1)

The skill bundle defines a comprehensive AI development pipeline but includes a high-risk tool, `super_dev_run`, which is described in `SKILL.md` as allowing the execution of arbitrary CLI commands. While the documentation in `references/commands.md` suggests this is intended for specific pipeline stages (e.g., `super-dev run frontend`), the unconstrained tool definition creates a significant Remote Code Execution (RCE) vulnerability. No clear evidence of intentional malice or data exfiltration was observed, but the broad execution capability is a major security concern.