← Scan another repo

github.com/obra/superpowers

@ 44c9b2d6e889

Submitted 8/4/2026, 10:25:51 AM · Status: ok

Risk grade
B
18 / 100
Findings
4
0 critical1 high3 medium0 low0 info0 on CISA KEV0ATT&CK
Showing 4 of 4 findings

Findings

  • Detected generic-api-key: Detected a Generic API Key, potentially exposing access to various services and sensitive operations
    Detected a Generic API Key, potentially exposing access to various services and sensitive operations.
    gitleaks
  • MD5/SHA1 is cryptographically broken for security use (integrity/signatures/ password hashing). Use SHA-256+ or a password KDF. (Apache-2.0.)
    MD5/SHA1 is cryptographically broken for security use (integrity/signatures/ password hashing). Use SHA-256+ or a password KDF. (Apache-2.0.)
    semgrepskills/brainstorming/scripts/server.cjs:13
  • Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    semgrepdocs/superpowers/plans/2026-06-11-visual-companion-final-hardening-fixup.md:331
  • Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    Possible hardcoded secret assigned to a credential-like variable. Move it to a secret store / env var. (First-party socbox rule; Apache-2.0.)
    semgrepdocs/superpowers/plans/2026-06-11-visual-companion-final-hardening-fixup.md:387

This report is public.