Superpowers is a set of skills, plain instruction files that coding agents load on demand, that turns an eager code generator into something closer to a careful engineer. Before writing code the agent asks what you are actually trying to build and shows the design back in short sections. Once you approve it, it writes a step-by-step plan, sets up a git worktree, and then works through the plan with true red-green test-driven development, a fresh subagent per task and a code review between tasks, finishing with a merge or pull request decision. Debugging, verification and parallel-agent skills round it out.
Jesse Vincent (obra) released it in October 2025 and it has become one of the most-starred skills libraries on GitHub, at about 295,000 stars, with his company Prime Radiant behind it. It is listed in Anthropic's official Claude Code plugin marketplace and also installs into Codex, Cursor, Gemini CLI, GitHub Copilot CLI, OpenCode, Hermes Agent and others. It is MIT-licensed, and the value is the methodology written into the skills rather than any app.
- Repository: github.com/obra/superpowers
- Licence: MIT (MIT License)
- Language: Shell. Stars: 294.6K. Forks: 26.3K. Last push: Sep 27, 2026.
- Scan: safe, Sep 25, 2026, commit 8ca22db
Who it is for
Developers who use Claude Code, Codex or a similar agent for real projects and want it to plan and test before it writes, rather than produce a large diff in one pass.
Getting started
1. Claude Code: install from Anthropic's official plugin marketplace
/plugin install superpowers@claude-plugins-official2. Gemini CLI
gemini extensions install https://github.com/obra/superpowers3. GitHub Copilot CLI: add the marketplace, then install
copilot plugin marketplace add obra/superpowers-marketplace && copilot plugin install superpowers@superpowers-marketplace4. Cursor: in Agent chat
/add-plugin superpowersInstall it separately in each agent you use; Codex users find it under Plugins in the app or with /plugins in the CLI. The optional visual companion loads a Prime Radiant logo that reports the Superpowers version; set SUPERPOWERS_DISABLE_TELEMETRY=1 (or Claude Code's DISABLE_TELEMETRY) to turn it off.
Safety scan
We cloned obra/superpowers at commit 8ca22db on Sep 25, 2026 and ran the checks described on the GitHub Tools page: credential patterns, decode-and-execute code, install-time scripts, committed binaries, risky CI workflows, every host the code talks to, known vulnerabilities in pinned dependencies, and project hygiene. A person read every hit. This is what we found.
- No secrets, no pattern hits, no committed binaries and no bare-IP URLs across 229 files and about 47,000 lines, 33,000 of them Markdown skill files you can read in full.
- hooks/session-start only reads the using-superpowers SKILL.md and hands it to the agent as context; it fetches nothing.
- The one installer-style script, skills/brainstorming/scripts/start-server.sh (210 lines), starts the visual companion's zero-dependency Node server on 127.0.0.1 and a random port with a per-project token. Its page loads the Prime Radiant logo from primeradiant.com with the Superpowers version in the request; SUPERPOWERS_DISABLE_TELEMETRY turns that off.
- Dependencies are effectively none: the only lockfile is a one-package test fixture, with no advisories.
- No workflows. Licence and code of conduct present; no security policy, Dependabot, CodeQL or contributing guide.
What the scanner counted
| Check | Result |
|---|---|
| Secrets | None found. |
| Suspicious code | None found. |
| Install-time code | 1 installer script |
| Committed binaries | None. |
| CI workflows | No GitHub Actions workflows. |
| Network hosts | 4 distinct hosts referenced from source; most often github.com, primeradiant.com, opencode.ai, code.claude.com. No URLs to bare IP addresses. |
| Known vulnerabilities | 0 advisories across 1 pinned package: 0 critical, 0 high, 0 moderate, 0 low. tests/brainstorm-server/package-lock.json: 1 packages, 0 advisories. |
| Project hygiene | Has licence file. Missing security policy, automated dependency updates, CodeQL, contributing guide. |
| OpenSSF Scorecard | Not scored: the project is not in Scorecard's weekly index. |
The raw findings
Every hit the scanner wrote out, with a link to the exact line at the scanned commit. Secrets candidates are redacted.
Installer scripts (1)
- skills/brainstorming/scripts/start-server.sh, 210 lines
By the numbers
| Stars | 294.6K |
|---|---|
| Forks | 26.3K |
| Contributors | 44 |
| Commits | 683 |
| Open issues | 157 |
| Open pull requests | 141 |
| Releases | 14 |
| Latest release | v6.4.2 |
| Licence | MIT |
| Main language | Shell |
| Project age | 11 months |
| Last push | Sep 27, 2026 |
| Tracked files | 229 |
| Lines of code | 46.8K |
| Checkout size | 2 MB |
Lines by language: Markdown 33K, Shell 7,593, JavaScript 4,734, Python 548, JSON 407, TypeScript 281.
Questions
Is Superpowers free?
Yes. Superpowers is MIT-licensed and free in every supported agent. Prime Radiant offers commercial support and tooling for companies, but the skills themselves are complete. The only cost is the extra model usage from planning, subagents and reviews, which uses more tokens than a single prompt.
Does Superpowers slow my agent down?
It adds steps on purpose: questions, a written design, a plan and reviews. For a one-line fix that is overhead. For multi-file features it tends to save time, because the agent can then work for long stretches without drifting from the plan. An executing-plans mode runs everything in one session with a single final review if you want it cheaper.
Does Superpowers send my code anywhere?
No. The skills are text instructions read by your agent; your code goes only where your agent already sends it. The one network call is the optional visual companion's logo, which includes the Superpowers version and nothing about your project, and it can be disabled.
This post is part of GitHub Tools, where every repository is cloned and scanned before it is written up. The scan is a snapshot of one commit on one day; the repository has moved on since, so check it before you install.
