{"data":{"skill":{"slug":"zhanlincui-using-superpowers","name":"using-superpowers","icon":"📦","repo":"https://github.com/ZhanlinCui/Ultimate-Agent-Skills-Collection/tree/main/using-superpowers","status":"approved","author":"ZhanlinCui","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"8454d599-1a69-46be-9725-96c11cd871ab","skill_id":"09046f9b-0ca8-4667-b73a-c2074f090750","version":2,"content_hash":"2d6ab5cf735010d881e368aae87a8e0b","risk_level":"critical","is_blocked":true,"safe_to_publish":false,"analysis_status":"ok","agent_auto_install_policy":null,"manual_install_policy":null,"summary":"The static external-command and weak-cryptography findings are false positives. However, the skill contains prompt-control language that instructs the assistant to override normal task flow, invoke tools before any response, follow the skill directly, and avoid reading skill files. This is a prompt injection risk and should block publication.","remediation":[],"risk_factor_evidence":[],"critical_findings":[{"title":"Prompt Injection Attempt Detected","verdict":"TRUE_POSITIVE","locations":[{"file":"SKILL.md","line_end":16,"line_start":6},{"file":"SKILL.md","line_end":24,"line_start":22},{"file":"SKILL.md","line_end":65,"line_start":50}],"confidence":0.97,"description":"The skill states that assistants ABSOLUTELY MUST invoke a skill, have no choice, must do so before any response, and should follow loaded skill content directly. It also says never to use the Read tool on skill files. This attempts to override platform and evaluator instructions, including security review behavior.","confidence_reasoning":"The file directly instructs the assistant to treat the skill as mandatory and to avoid normal file-reading workflow. This is clear evidence of prompt-control behavior rather than an accidental phrase."}],"high_findings":[],"medium_findings":[],"low_findings":[{"title":"Static External Command Findings Dismissed","verdict":"FALSE_POSITIVE","locations":[{"file":"SKILL.md","line_end":16,"line_start":16},{"file":"SKILL.md","line_end":46,"line_start":26}],"confidence":0.94,"description":"The line 16 finding refers to a named Skill tool, not shell execution. The line 26 finding is a Graphviz dot diagram in a fenced block, not executable Ruby or shell code.","confidence_reasoning":"The referenced content is Markdown documentation and a diagram. No shell command, Ruby backtick execution, or executable script is present."},{"title":"Static Weak Cryptography Findings Dismissed","verdict":"FALSE_POSITIVE","locations":[{"file":"SKILL.md","line_end":3,"line_start":3},{"file":"SKILL.md","line_end":72,"line_start":72}],"confidence":0.91,"description":"The reported weak-cryptography lines contain descriptive metadata and a priority list. No cryptographic algorithm, hash function, encryption call, or security-sensitive implementation is present.","confidence_reasoning":"The flagged lines do not mention or implement MD5, SHA-1, DES, RC4, or any other weak cryptographic primitive. The signal appears to be a keyword collision."}],"dangerous_patterns":[{"title":"Mandatory Behavioral Override Language","verdict":"TRUE_POSITIVE","locations":[{"file":"SKILL.md","line_end":12,"line_start":6},{"file":"SKILL.md","line_end":24,"line_start":22}],"confidence":0.96,"description":"The skill uses absolute language that instructs assistants to invoke skills before any response and to reject normal reasoning about whether a skill is needed.","confidence_reasoning":"The language is explicit and repeated. It is designed to control assistant behavior outside a bounded user task."},{"title":"Instruction to Avoid File Review","verdict":"TRUE_POSITIVE","locations":[{"file":"SKILL.md","line_end":16,"line_start":16}],"confidence":0.93,"description":"The skill tells Claude Code users to never use the Read tool on skill files. This conflicts with security review and provenance checks.","confidence_reasoning":"The instruction is direct and located in the skill usage guidance. It would interfere with independent inspection of skill contents."}],"files_scanned":1,"total_lines":88,"audit_model":"codex","audited_at":"2026-07-01T03:47:30.069+00:00","created_at":"2026-07-01T04:01:07.448478+00:00","static_findings":[],"finding_verdicts":[],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"canonical install advisories are incomplete"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"critical","confirmedFindingCount":1,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":2,"agentAutoInstallPolicy":null,"manualInstallPolicy":null,"artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}