Superpowers Dev Workflow
Spec-first, TDD, subagent-driven software development workflow. Use when: (1) building any new feature or app — triggers brainstorm → plan → subagent executi...
references/brainstorming.md
text/markdown · 1433 bytes
references/finishing-branch.md
text/markdown · 2313 bytes
references/subagent-development.md
text/markdown · 3083 bytes
references/systematic-debugging.md
text/markdown · 2914 bytes
references/tdd.md
text/markdown · 2527 bytes
references/writing-plans.md
text/markdown · 1995 bytes
SKILL.md
text/markdown · 4774 bytes
skill-card.md
text/markdown · 2764 bytes
Security Scan
Status
clean
OpenClaw
Official security analysis
OpenClaw analysis
This is a disclosed software-development workflow skill; its command use, subagents, commits, and branch actions fit that purpose and include user gates for higher-impact steps.
Confidence: high
VirusTotal
Type: OpenClaw Skill Name: superpowers Version: 1.0.0 This skill bundle is suspicious due to its extensive use of powerful execution capabilities (`exec`, `sessions_spawn`) and dynamic command generation. Files like `SKILL.md`, `references/finishing-branch.md`, and `references/writing-plans.md` instruct the agent to construct and execute various shell commands (`git`, `gh`, `pytest`, `pnpm test`, `cargo test`, `go test`) using potentially user-controlled input (e.g., branch names, PR titles). This creates a significant risk of prompt injection and shell injection if user input is not rigorously sanitized, allowing an attacker to execute arbitrary commands or manipulate sub-agent behavior. While the skill's stated purpose is legitimate software development, the inherent power and lack of explicit input sanitization for command construction elevate it beyond benign.