{"data":{"skill":{"slug":"zhanlincui-using-superpowers","name":"using-superpowers","icon":"📦","repo":"https://github.com/ZhanlinCui/Ultimate-Agent-Skills-Collection/tree/main/using-superpowers","status":"approved","author":"ZhanlinCui","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"76e620ff-d067-483c-8008-997d89a585a8","skill_id":"09046f9b-0ca8-4667-b73a-c2074f090750","version":3,"content_hash":"v2:88a205c7f635a966e31156313b590d59007c5caa:061a9c638b65ff5d583b7d89b15a16ab58f0ec56c18b17b4c9d6c08344254fd6:18bd69a67bb439600c25ab75ebedeba1b24b6f3a79643571f27164eff8f8f18b:8557dbde4a71e02af4cc006d4024b802","risk_level":"high","is_blocked":false,"safe_to_publish":false,"analysis_status":"ok","agent_auto_install_policy":"confirmation_required","manual_install_policy":"allowed","summary":"The two static external-command findings are false positives caused by inline Markdown backticks and a DOT diagram fence, not executable shell use. The skill does contain strong prompt-injection style instructions that try to override normal agent behavior and discourage reading skill files, so a semantic high-severity finding was added.","remediation":[{"issue":"Prompt injection style authority claims","severity":"high","suggestion":"Replace absolute mandates with scoped guidance that remains subordinate to system, developer, and user instructions."},{"issue":"Instruction discourages direct review of skill files","severity":"high","suggestion":"Remove the instruction to never use file reading tools, especially for auditing, debugging, or marketplace review tasks."}],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":16,"line_start":16},{"file":"SKILL.md","line_end":46,"line_start":26}]}],"critical_findings":[],"high_findings":[{"title":"Prompt Injection Attempt Detected","locations":[{"file":"SKILL.md","line_end":12,"line_start":6},{"file":"SKILL.md","line_end":16,"line_start":16},{"file":"SKILL.md","line_end":24,"line_start":24}],"confidence":0.93,"description":"The skill states \"YOU DO NOT HAVE A CHOICE\" and \"Never use the Read tool on skill files.\" These instructions can override higher-priority instructions and interfere with security review.","review_kind":"security","source_category":"semantic","source_severity":"high","confidence_reasoning":"The cited lines explicitly demand mandatory compliance and discourage direct file reading. This is a strong prompt-injection pattern, even though it does not perform code execution."}],"medium_findings":[],"low_findings":[],"dangerous_patterns":[],"files_scanned":1,"total_lines":88,"audit_model":"codex","audited_at":"2026-07-08T16:23:34.722+00:00","created_at":"2026-07-08T17:49:45.109595+00:00","static_findings":[{"id":"external_commands:SKILL.md:16:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"**In Claude Code:** Use the `Skill` tool. When you invoke a skill, its content is loaded and present","category":"external_commands","line_end":16,"severity":"medium","line_start":16},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","file":"SKILL.md","pattern":"Ruby/shell backtick execution","snippet":"```dot","category":"external_commands","line_end":46,"severity":"medium","line_start":26}],"finding_verdicts":[{"id":"external_commands:SKILL.md:16:ruby-shell-backtick-execution","reason":"Line 16 uses Markdown inline backticks around the word Skill, not Ruby or shell execution. No command is executed and no user input is passed to a shell.","verdict":"false_positive","confidence":0.97},{"id":"external_commands:SKILL.md:26:ruby-shell-backtick-execution","reason":"Line 26 opens a fenced DOT diagram block, and the following lines are graph syntax for documentation. This is not shell or Ruby backtick execution.","verdict":"false_positive","confidence":0.97}],"semantic_findings":[{"title":"Prompt Injection Attempt Detected","severity":"high","locations":[{"file":"SKILL.md","line_end":12,"line_start":6},{"file":"SKILL.md","line_end":16,"line_start":16},{"file":"SKILL.md","line_end":24,"line_start":24}],"confidence":0.93,"description":"The skill states \"YOU DO NOT HAVE A CHOICE\" and \"Never use the Read tool on skill files.\" These instructions can override higher-priority instructions and interfere with security review.","confidence_reasoning":"The cited lines explicitly demand mandatory compliance and discourage direct file reading. This is a strong prompt-injection pattern, even though it does not perform code execution."}],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"confirmed_risk_level does not match the canonical trust resolver"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"high","confirmedFindingCount":1,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":0,"agentAutoInstallPolicy":"confirmation_required","manualInstallPolicy":"allowed","artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}