{"data":{"skill":{"slug":"sickn33-using-superpowers","name":"using-superpowers","icon":"📦","repo":"https://github.com/sickn33/antigravity-awesome-skills/tree/main/skills/using-superpowers","status":"approved","author":"sickn33","authorVersion":null,"skillstoreRevision":1},"audit":{"id":"c7ce4cd3-420d-47b5-be96-8cafcf5e8590","skill_id":"9a9f1f92-cc18-4203-84e4-7ef0845dc06b","version":4,"content_hash":"v3:f93e9bb0daca99badb6a7e574b97737155d57cb3:81d921b16502091f44e8669bbcfae74b87bbf4295d03fff70a98e81d73af60a6:11b58012deac7f51df13b695d94bba7c0e05f88a71f90053dc4ef4a90e6fdb4e:736b696c6c732f7369636b6e33332f7573696e672d7375706572706f77657273:507cf55c1ff380016fa1ade7fa07cf59","risk_level":"high","is_blocked":false,"safe_to_publish":false,"analysis_status":"ok","agent_auto_install_policy":"confirmation_required","manual_install_policy":"allowed","summary":"The two static external command findings are false positives caused by markdown inline code and a DOT diagram. No executable code, shell invocation, network access, or filesystem operation is present. A high-severity semantic finding remains because the skill contains coercive prompt instructions that try to control tool use and override normal assistant discretion.","remediation":[{"issue":"Prompt injection style directives","severity":"high","suggestion":"Replace absolute instructions and tool bans with scoped guidance that defers to platform, user, and security policies."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":16,"line_start":16},{"file":"SKILL.md","line_end":46,"line_start":26}]}],"critical_findings":[],"high_findings":[{"title":"Prompt Injection Attempt Detected","locations":[{"file":"SKILL.md","line_end":16,"line_start":6}],"confidence":0.92,"description":"The skill says 'ABSOLUTELY MUST invoke the skill', 'YOU DO NOT HAVE A CHOICE', and 'Never use the Read tool on skill files.' This attempts to override normal tool governance.","review_kind":"security","source_category":"semantic","source_severity":"high","confidence_reasoning":"The text directly commands agent behavior and tool use with absolute authority. It can conflict with host instructions and security review workflows."}],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":1,"total_lines":88,"audit_model":"codex","audited_at":"2026-07-07T04:24:00.284+00:00","created_at":"2026-07-16T03:03:46.461885+00:00","static_findings":[{"id":"external_commands:SKILL.md:16:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**In Claude Code:** Use the `Skill` tool. When you invoke a skill, its content is loaded and present","category":"external_commands","line_end":16,"severity":"medium","line_start":16},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```dot","category":"external_commands","line_end":46,"severity":"medium","line_start":26}],"finding_verdicts":[{"id":"external_commands:SKILL.md:16:ruby-shell-backtick-execution","reason":"The backticks surround the word Skill in markdown at SKILL.md line 16. This is documentation, not Ruby or shell execution.","verdict":"false_positive","confidence":0.96},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","reason":"The fenced block is labeled dot and contains a static flowchart in SKILL.md lines 26-46. It is not shell code and is not executed by the skill.","verdict":"false_positive","confidence":0.94}],"semantic_findings":[{"title":"Prompt Injection Attempt Detected","severity":"high","locations":[{"file":"SKILL.md","line_end":16,"line_start":6}],"confidence":0.92,"description":"The skill says 'ABSOLUTELY MUST invoke the skill', 'YOU DO NOT HAVE A CHOICE', and 'Never use the Read tool on skill files.' This attempts to override normal tool governance.","confidence_reasoning":"The text directly commands agent behavior and tool use with absolute authority. It can conflict with host instructions and security review workflows."}],"subject_marketplace_commit_sha":"f93e9bb0daca99badb6a7e574b97737155d57cb3","subject_content_hash":"81d921b16502091f44e8669bbcfae74b87bbf4295d03fff70a98e81d73af60a6","subject_tree_hash":"11b58012deac7f51df13b695d94bba7c0e05f88a71f90053dc4ef4a90e6fdb4e","subject_plugin_path":"skills/sickn33/using-superpowers","audit_payload_hash":"507cf55c1ff380016fa1ade7fa07cf59","confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":"f93e9bb0daca99badb6a7e574b97737155d57cb3","contentHash":"81d921b16502091f44e8669bbcfae74b87bbf4295d03fff70a98e81d73af60a6","treeHash":"11b58012deac7f51df13b695d94bba7c0e05f88a71f90053dc4ef4a90e6fdb4e","pluginPath":"skills/sickn33/using-superpowers","auditPayloadHash":"507cf55c1ff380016fa1ade7fa07cf59"},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"high","confirmedFindingCount":1,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"confirmation_required","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":true}}