Superpowers Dev Workflow
Spec-first, TDD, subagent-driven software development workflow. Use when: (1) building any new feature or app — triggers brainstorm → plan → subagent executi...
v1.0.0
2026/02/27
Initial port of obra/superpowers for OpenClaw — spec-first, TDD, subagent-driven development workflow
Security Scan
Status
clean
OpenClaw
Official security analysis
OpenClaw analysis
This is a disclosed software-development workflow skill; its command use, subagents, commits, and branch actions fit that purpose and include user gates for higher-impact steps.
Confidence: high
VirusTotal
Type: OpenClaw Skill Name: superpowers Version: 1.0.0 This skill bundle is suspicious due to its extensive use of powerful execution capabilities (`exec`, `sessions_spawn`) and dynamic command generation. Files like `SKILL.md`, `references/finishing-branch.md`, and `references/writing-plans.md` instruct the agent to construct and execute various shell commands (`git`, `gh`, `pytest`, `pnpm test`, `cargo test`, `go test`) using potentially user-controlled input (e.g., branch names, PR titles). This creates a significant risk of prompt injection and shell injection if user input is not rigorously sanitized, allowing an attacker to execute arbitrary commands or manipulate sub-agent behavior. While the skill's stated purpose is legitimate software development, the inherent power and lack of explicit input sanitization for command construction elevate it beyond benign.