continuous-learning-v2
Pass
Audited by Gen Agent Trust Hub on Mar 31, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill executes shell commands to manage its lifecycle and detect context.
scripts/instinct-cli.pyusessubprocess.runto callgitfor project identification and remote URL detection.agents/observer-loop.shandagents/start-observer.shexecute theclaudeCLI to perform background analysis of session logs using the Haiku model.- [EXTERNAL_DOWNLOADS]: The
importcommand inscripts/instinct-cli.pyallows fetching instinct definitions from remote URLs. - Evidence: The script uses
urllib.request.urlopen(source)to download content from user-provided web sources which are then parsed as instructions. - [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its core 'learning' mechanism where session data influences future behavior.
- Ingestion points:
hooks/observe.shcaptures all tool inputs and outputs (which may contain untrusted data from the web or files) and stores them inobservations.jsonlwithin project directories. - Boundary markers: The prompt used by the background observer in
agents/observer-loop.shinterpolates the collected observations without strong delimiters or explicit instructions to ignore embedded commands, allowing malicious data to potentially override the observer's logic. - Capability inventory: The skill possesses the capability to write new instruction files (instincts, skills, and commands) to the filesystem via
scripts/instinct-cli.pyandagents/observer-loop.sh, which are then interpreted by the agent. It also executes theclaudeCLI with generated prompts. - Sanitization: The skill implements a regex-based secret scrubber in
hooks/observe.shto remove API keys and tokens from logs, but it does not perform any sanitization to prevent prompt injection or instruction hijacking from malicious tool outputs.
Audit Metadata