continuous-learning

Pass

Audited by Gen Agent Trust Hub on Apr 1, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface identified in the automated learning workflow. The skill prompts the agent to analyze session transcripts which may contain malicious instructions from external sources encountered during the session.\n
  • Ingestion points: The evaluate-session.sh script identifies the session transcript via transcript_path extracted from the platform's hook input.\n
  • Boundary markers: None. The skill lacks delimiters or instructions for the agent to ignore potentially malicious content embedded in the transcript during analysis.\n
  • Capability inventory: The skill facilitates the creation of new executable skill files in ~/.claude/skills/learned/ based on the analysis of these transcripts.\n
  • Sanitization: No validation or filtering is performed on the transcript content before it is signaled to the agent for pattern extraction.\n- [COMMAND_EXECUTION]: Local Shell Hook Execution. The skill uses a bash script (evaluate-session.sh) as a lifecycle 'Stop' hook to manage local directories and perform filesystem reads. While the operations (mkdir, grep) are standard for the tool's purpose, the script runs automatically at the end of every session and provides the capability for automated file management within the agent's environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 1, 2026, 11:09 AM
Security Audit — agent-trust-hub — continuous-learning