REPOSITORY EVIDENCE / INDEXABLE REPORT

obra/superpowers — MCP & Agent Security Evidence Report

No MCP configuration evidence was observed in the selected bounded scan. Observed evidence classes: Download / install, Agent permissions / behavior, Supply-chain / dependencies. Evidence observations are review signals, not a safe/unsafe verdict.

Is obra/superpowers safe to run?

ShadowMCP does not issue a safe/unsafe verdict. This report shows bounded repository evidence that can help identify what deserves review before running or approving the project.

Scan identity

Report schemashadowmcp.repo-evidence.v9
Scannershadowmcp.web-repo-scan.v22
Scan completed2026-09-19T16:07:07.676Z
Repository branchmain
Scanned commit5bf4e78011075bcfc0dc295f0724994cd123ee71
Indexation gateIndexable quality gate passed.

Evidence summary

Review priority
Priority review

This is a triage priority, not a repository risk rating.

No MCP configuration evidence was observed in the selected bounded scan. Observed evidence classes: Download / install, Agent permissions / behavior, Supply-chain / dependencies. Evidence observations are review signals, not a safe/unsafe verdict.

Evidence categories

Shell / command execution

Not found in scanned scope

No matching evidence was observed in the selected bounded scan scope. This is not proof of absence elsewhere.

Download / install

Found

Selected evidence was observed. This does not prove a vulnerability, malicious behavior or unsafe operation.

  • README.mdgit clone
  • scripts/sync-to-codex-plugin.shgit clone

MCP configuration

Not found in scanned scope

No matching evidence was observed in the selected bounded scan scope. This is not proof of absence elsewhere.

Agent permissions / behavior

Found

Selected evidence was observed. This does not prove a vulnerability, malicious behavior or unsafe operation.

  • AGENTS.mdagent instruction/config file · tools / permissions, hooks, agent instructions, model config
  • CLAUDE.mdagent instruction/config file · agent instructions
  • GEMINI.mdagent instruction/config file · tools / permissions
  • scripts/package-codex-plugin.shhooks, agent instructions
  • scripts/sync-to-codex-plugin.shhooks, agent instructions

CI/CD automation

Not found in scanned scope

No matching evidence was observed in the selected bounded scan scope. This is not proof of absence elsewhere.

Supply-chain / dependencies

Found

Selected evidence was observed. This does not prove a vulnerability, malicious behavior or unsafe operation.

  • package.jsonparsed package manifest · 0 declared dependency entries

Scope and limitations

Scan mode: BOUNDED_ROOT_AND_SELECTED_DEPTH1. General recursive crawl: NO.

  • Public, selected and bounded repository evidence only.
  • FOUND means evidence observed, not risk or malicious behavior proven.
  • NOT_FOUND_IN_SCANNED_SCOPE is not proof of absence outside the bounded scan.
  • Trust/community metadata is descriptive context, not a security guarantee.
  • Zero selected dependency evidence does not mean zero dependencies.
  • No repository clone or target-code execution.
  • No raw source-file bodies or secret/token values are included in this report.
  • No general recursive crawl.
  • No CVE lookup, package reputation lookup or package registry lookup.
  • No numeric security score and no safe/unsafe verdict.

Repository context

Trust/community metadata is descriptive context only; it is not a security guarantee.

Repository age / activitycreated 2025-10-09 · 344 days old · last push 2026-09-19 · 0 days since last push
Community signalsstars 288740 · forks 25824 · open issues 369
OwnershipUser · obra
LicenseMIT
Repository statearchived NO · fork NO · default branch main

Continue the review