continuous-learning-agent
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill implements a workflow where agents persist logs and patterns in local markdown files (
.claude/learnings/) and are instructed to review this context at the start of new sessions. This creates an indirect prompt injection surface: if an agent logs untrusted data from a previous task (such as a malicious error message or poisoned external content), those instructions could be re-ingested and followed by the agent in future sessions during the review phase. - [COMMAND_EXECUTION]: The skill provides several bash utility snippets and a
post-task.shscript for directory management and file searching. These operations use standard commands (mkdir,echo,cat,grep) and do not perform malicious actions or request elevated privileges.
Audit Metadata