🦾 MONSTER ENGINEER v2 - Ultimate AI CLI with 63 Skills, 12 Superpowers, 14 Agents. Multi-Agent Orchestration, Cost-Aware, Security Scorecard, Parallel-First.
Drift inferred · capture-to-capture
- HIGH code analysis flagged hidden prompt content in claude-all-config
transport stdio · http counts 0 tools · 0 res
· 0 prompts
permission surface via code analysis
no tools enumerated yet for this server.
prompt-surface
shipped agent-instruction files + hidden-content / dangerous-code findings —
quoted from the analyzed source
analyzed v3.9.0 · analyzer v17 · 1d ago
skills & prompt files 94
- ⚠ hidden: skill: skill-exfilpackage/skills/telegram-alerts/SKILL.md:62
secret→sink: ### Via Telegram Bot API Direct
- agent-rulespackage/CLAUDE.md
- skillpackage/skills/agent-workflow-designer/SKILL.md
- skillpackage/skills/agents-md-generator/SKILL.md
- skillpackage/skills/api-design-authority/SKILL.md
- skillpackage/skills/api-design-reviewer/SKILL.md
- skillpackage/skills/api-development/SKILL.md
- skillpackage/skills/architecture-decisions/SKILL.md
- skillpackage/skills/artifacts-builder/SKILL.md
- skillpackage/skills/auto-backup/SKILL.md
- skillpackage/skills/auto-recall-memory/SKILL.md
- skillpackage/skills/backend-dev/SKILL.md
- skillpackage/skills/brainstorming/SKILL.md
- skillpackage/skills/browser/SKILL.md
- skillpackage/skills/capacity-planner/SKILL.md
- skillpackage/skills/changelog-generator/SKILL.md
- skillpackage/skills/chaos-engineering/SKILL.md
- skillpackage/skills/code-quality/SKILL.md
- skillpackage/skills/code-refactoring/SKILL.md
- skillpackage/skills/code-review-authority/SKILL.md
- skillpackage/skills/condition-based-waiting/SKILL.md
- skillpackage/skills/consensus-voting/SKILL.md
- skillpackage/skills/cost-aware-execution/SKILL.md
- skillpackage/skills/cost-tracker/SKILL.md
- skillpackage/skills/crisis-commander/SKILL.md
- skillpackage/skills/data-quality-auditor/SKILL.md
- skillpackage/skills/database-design/SKILL.md
- skillpackage/skills/database-development/SKILL.md
- skillpackage/skills/defense-in-depth/SKILL.md
- skillpackage/skills/dependency-scanner/SKILL.md
- skillpackage/skills/deployment/SKILL.md
- skillpackage/skills/dispatching-parallel-agents/SKILL.md
- skillpackage/skills/documentation-generation/SKILL.md
- skillpackage/skills/error-handling/SKILL.md
- skillpackage/skills/executing-plans/SKILL.md
- skillpackage/skills/finishing-a-development-branch/SKILL.md
- skillpackage/skills/frontend-design/frontend-design/SKILL.md
- skillpackage/skills/frontend-ui-integration/SKILL.md
- skillpackage/skills/incident-response/SKILL.md
- skillpackage/skills/integration-testing/SKILL.md
- skillpackage/skills/javascript-typescript/SKILL.md
- skillpackage/skills/kubernetes-operator/SKILL.md
- skillpackage/skills/llm-cost-optimizer/SKILL.md
- skillpackage/skills/log-intelligence/SKILL.md
- skillpackage/skills/logging-monitoring/SKILL.md
- skillpackage/skills/migration-architect/SKILL.md
- skillpackage/skills/mobile-development/SKILL.md
- skillpackage/skills/multi-vps/SKILL.md
- skillpackage/skills/observability-designer/SKILL.md
- skillpackage/skills/performance-baseline/SKILL.md
- skillpackage/skills/performance-optimization/SKILL.md
- agent-rulespackage/skills/playwright-pro/CLAUDE.md
- skillpackage/skills/playwright-pro/SKILL.md
- skillpackage/skills/playwright-pro/skills/browserstack/SKILL.md
- skillpackage/skills/playwright-pro/skills/coverage/SKILL.md
- skillpackage/skills/playwright-pro/skills/fix/SKILL.md
- skillpackage/skills/playwright-pro/skills/generate/SKILL.md
- skillpackage/skills/playwright-pro/skills/init/SKILL.md
- skillpackage/skills/playwright-pro/skills/migrate/SKILL.md
- skillpackage/skills/playwright-pro/skills/pw/SKILL.md
- skillpackage/skills/playwright-pro/skills/report/SKILL.md
- skillpackage/skills/playwright-pro/skills/review/SKILL.md
- skillpackage/skills/playwright-pro/skills/testrail/SKILL.md
- skillpackage/skills/prompt-governance/SKILL.md
- skillpackage/skills/python-development/SKILL.md
- skillpackage/skills/rag-architect/SKILL.md
- skillpackage/skills/receiving-code-review/SKILL.md
- skillpackage/skills/refactoring/SKILL.md
- skillpackage/skills/requesting-code-review/SKILL.md
- skillpackage/skills/root-cause-tracing/SKILL.md
- skillpackage/skills/security-auditor-supreme/SKILL.md
- skillpackage/skills/security-review/SKILL.md
- skillpackage/skills/self-validation-loop/SKILL.md
- skillpackage/skills/sharing-skills/SKILL.md
- skillpackage/skills/skill-creator/SKILL.md
- skillpackage/skills/standard-architecture/SKILL.md
- skillpackage/skills/stress-test/SKILL.md
- skillpackage/skills/subagent-driven-development/SKILL.md
- skillpackage/skills/systematic-debugging/SKILL.md
- skillpackage/skills/tech-debt-hunter/SKILL.md
- skillpackage/skills/tech-stack-authority/SKILL.md
- skillpackage/skills/terraform-patterns/SKILL.md
- skillpackage/skills/test-driven-development/SKILL.md
- skillpackage/skills/testing-anti-patterns/SKILL.md
- skillpackage/skills/testing-skills-with-subagents/SKILL.md
- skillpackage/skills/threat-detection/SKILL.md
- skillpackage/skills/ui-ux-pro-max/SKILL.md
- skillpackage/skills/ui-ux-review/SKILL.md
- skillpackage/skills/using-git-worktrees/SKILL.md
- skillpackage/skills/using-superpowers/SKILL.md
- skillpackage/skills/verification-before-completion/SKILL.md
- skillpackage/skills/whatsapp-business-platform/SKILL.md
- skillpackage/skills/writing-plans/SKILL.md
- skillpackage/skills/writing-skills/SKILL.md
evidence-backed
findings quoted directly from the published source artifact — not inferred
filesystem 15
- fs package/bin/mcp-install.js :3
const fs = require('fs'); - fs package/bin/skills-cli.js :17
const fs = require('fs'); - fs package/index.js :23
const fs = require('fs'); - fs package/lib/skill-hooks.js :13
const fs = require('fs'); - fs package/lib/skills-core.js :1
import fs from 'fs'; - fs package/postinstall.js :7
const fs = require('fs'); - fs package/skills/performance-optimization/profiling/profile.template.js :2
const fs = require('fs'); - fs package/tmux/bin/tmux-setup.js :3
const fs = require('fs'); - fs package/tmux/install.js :6
const fs = require('fs'); - fs package/utils/config.js :7
const fs = require('fs'); - fs package/utils/custom-claude-lib.js :8
const fs = require('fs').promises; - fs package/utils/install-superpowers.js :8
const fs = require('fs'); - fs package/utils/install.js :8
const fs = require('fs'); - fs package/utils/postinstall.js :7
const fs = require('fs'); - fs package/utils/uninstall-superpowers.js :8
const fs = require('fs');
shell / exec 9
- shell package/bin/skills-cli.js :19
const { execSync } = require('child_process'); - shell package/lib/skill-hooks.js :15
const { execSync } = require('child_process'); - shell package/lib/skills-core.js :3
import { execSync } from 'child_process'; - shell package/postinstall.js :9
const { execSync } = require('child_process'); - shell package/tmux/bin/tmux-setup.js :6
const { execSync } = require('child_process'); - shell package/utils/custom-claude-lib.js :130
const { exec } = require('child_process'); - shell package/utils/install-superpowers.js :11
const { execSync } = require('child_process'); - shell package/utils/install.js :10
const { execSync } = require('child_process'); - shell package/utils/postinstall.js :9
const { execSync } = require('child_process');
network 3
- net package/bin/mcp-install.js :2
const https = require('https'); - net package/skills/playwright-pro/integrations/browserstack-mcp/src/client.ts :36
const response = await fetch(url, options); - net package/skills/playwright-pro/integrations/testrail-mcp/src/client.ts :40
const response = await fetch(url, options);
secrets 2
- secrets package/skills/playwright-pro/integrations/browserstack-mcp/src/index.ts :13
accessKey: process.env.BROWSERSTACK_ACCESS_KEY ?? '', - secrets package/skills/playwright-pro/integrations/testrail-mcp/src/index.ts :14
apiKey: process.env.TESTRAIL_API_KEY ?? '',
install hooks 1
- postinstall (suspicious) package/package.json :16
node postinstall.js || bash install.sh