Versioned security assessment

Report ID: SA-2D6AB5CF

7/1/2026, 3:47:30 AM

using-superpowers security assessment v2

Skill Security Certification Report

Audit History
Audit model: codex Historical report
Skill name
using-superpowers
Version
v2
Maintainer
ZhanlinCui
Coverage
1 Files scanned · 88 Lines analyzed
Policy version
Unavailable

Highest confirmed finding severity

Critical

1 confirmed security finding requires attention.

Installation context

Historical evidence

This report may not describe the currently installable artifact. Open the current Skill page for install guidance.

Open current Skill page

This report does not block or authorize the manifest or ZIP.

The static external-command and weak-cryptography findings are false positives. However, the skill contains prompt-control language that instructs the assistant to override normal task flow, invoke tools before any response, follow the skill directly, and avoid reading skill files. This is a prompt injection risk and should block publication.

Report position

Historical report

Open audit history before using this report to install.

Audit attestation

Not attestable

The required immutable binding is incomplete.

Human verification

Not verified

No human verification is recorded for this report.

Coverage

1 Files scanned · 88 Lines analyzed

1 item shown for review

Limitations

This report does not claim runtime or sandbox execution and does not prove the absence of side effects.

Evidence chain

Follow the evidence from source binding to the install contract. Available evidence supports verification; it is not a safety guarantee.

  1. Source

    Binding unavailable

  2. Artifact

    Identity incomplete

  3. Audit

    Complete

  4. Install contract

    Open manifest to verify

    Open manifest

Capabilities observed

Observed means this report recorded supporting evidence. Not recorded does not prove that a capability is absent.

Contains scripts

May execute code included with the Skill.

Not recorded by this audit

Network access

May connect to external services.

Not recorded by this audit

Filesystem access

May read or write local files.

Not recorded by this audit

Env variables

May read values from the process environment.

Not recorded by this audit

External commands

May invoke commands or programs outside the Skill.

Not recorded by this audit

Risk findings

Confirmed security concerns are separated from items that still need review.

Confirmed security concerns (1)

RISK-001 Critical
Prompt Injection Attempt Detected
The skill states that assistants ABSOLUTELY MUST invoke a skill, have no choice, must do so before any response, and should follow loaded skill content directly. It also says never to use the Read tool on skill files. This attempts to override platform and evaluator instructions, including security review behavior.
The file directly instructs the assistant to treat the skill as mandatory and to avoid normal file-reading workflow. This is clear evidence of prompt-control behavior rather than an accidental phrase.

Expert evidence

Immutable subject identity, scanner metadata, dismissed matches, and source-level evidence.

Artifact subject

Marketplace commit
Unavailable
Content hash
Unavailable
Tree hash
Unavailable
Skill path
Unavailable
Audit payload hash
Unavailable

Analysis metadata

Audit model: codex

Analysis state: Complete

Scope is limited to the recorded files, lines, methods, and evidence. No runtime or sandbox execution is claimed.

Static false positives ignored (2)
Low
Static External Command Findings Dismissed
The line 16 finding refers to a named Skill tool, not shell execution. The line 26 finding is a Graphviz dot diagram in a fenced block, not executable Ruby or shell code.
The referenced content is Markdown documentation and a diagram. No shell command, Ruby backtick execution, or executable script is present.
Low
Static Weak Cryptography Findings Dismissed
The reported weak-cryptography lines contain descriptive metadata and a priority list. No cryptographic algorithm, hash function, encryption call, or security-sensitive implementation is present.
The flagged lines do not mention or implement MD5, SHA-1, DES, RC4, or any other weak cryptographic primitive. The signal appears to be a keyword collision.

Verify and export

The manifest and lockfile bind install artifacts to cryptographic hashes. This integrity claim is separate from the security assessment.

Audit attestation: not_attestable