Back to skill

Security audit

Using Superpowers

Security checks for vulnerabilities and agentic risk

Overview

This skill is not malware, but it broadly forces agent behavior and downstream skill loading across nearly every conversation.

Review before installing. This skill may be useful as a discipline reminder, but it intentionally changes the agent's decision flow across conversations and can pressure the agent to load and follow other skills too early. Keep normal instruction priority, safety checks, and user confirmation for sensitive actions in place.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (1)

T01 · Skill Instruction Hijacking

Error
Location
SKILL.md:6
Finding

Mandatory Skill Invocation Hijacks Agent Workflow and Decision-Making

Content
View full analysis
If you think there is even a 1% chance a skill might apply to what you are doing, you ABSOLUTELY MUST invoke the skill. IF A SKILL APPLIES TO YOUR TASK, YOU DO NOT HAVE A CHOICE. YOU MUST USE IT. This is not negotiable. This is not optional. You cannot rationalize your way out of this. ``` ```markdown ## The Rule **Invoke relevant or requested skills BEFORE any response or action.** Even a 1% chance a skill might apply means that you should invoke the skill to check. If an invoked skill turns out to be wrong for the situation, you don't need to use it. ``` ```markdown ## Red Flags These thoughts mean STOP—you're rationalizing: | Thought | Reality | |---------|---------| | "This is just a simple question" | Questions are tasks. Check for skills. | | "I need more context first" | Skill check comes BEFORE clarifying questions. | | "Let me explore the codebase first" | Skills tell you HOW to explore. Check first. | | "I can check git/files quickly" | Files lack conversation context. Check for skills. | | "Let me gather information first" | Skills tell you HOW to gather information. | | "This doesn't need a formal skill" | If a skill exists, use it. | | "I remember this skill" | Skills evolve. Read current version. | | "This doesn't count as a task" | Action = task. Check for skills. | | "The skill is overkill" | Simple things become complex. Use it. | | "I'll just do this one thing first" | Check BEFORE doing anything. | | "This feels productive" | Undisciplined action wastes time. Skills prevent this. | | "I know what that means" | Knowing the concept ≠ using the skill. Invoke it. | ``` ### Technical Analysis The skill establishes a global behavioral rule that a ...[truncated 2961 chars]
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill description and body mandate invocation at the start of essentially any conversation, including before clarifying questions, making the trigger scope effectively universal. This can force unnecessary skill loading and obedience to downstream instructions, increasing the attack surface for prompt-injection-style workflow hijacking and reducing the agent's ability to apply narrower, task-appropriate safeguards.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.