continuous-learning-v2

Pass

Audited by Gen Agent Trust Hub on Mar 31, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes shell commands to manage its lifecycle and detect context.
  • scripts/instinct-cli.py uses subprocess.run to call git for project identification and remote URL detection.
  • agents/observer-loop.sh and agents/start-observer.sh execute the claude CLI to perform background analysis of session logs using the Haiku model.
  • [EXTERNAL_DOWNLOADS]: The import command in scripts/instinct-cli.py allows fetching instinct definitions from remote URLs.
  • Evidence: The script uses urllib.request.urlopen(source) to download content from user-provided web sources which are then parsed as instructions.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its core 'learning' mechanism where session data influences future behavior.
  • Ingestion points: hooks/observe.sh captures all tool inputs and outputs (which may contain untrusted data from the web or files) and stores them in observations.jsonl within project directories.
  • Boundary markers: The prompt used by the background observer in agents/observer-loop.sh interpolates the collected observations without strong delimiters or explicit instructions to ignore embedded commands, allowing malicious data to potentially override the observer's logic.
  • Capability inventory: The skill possesses the capability to write new instruction files (instincts, skills, and commands) to the filesystem via scripts/instinct-cli.py and agents/observer-loop.sh, which are then interpreted by the agent. It also executes the claude CLI with generated prompts.
  • Sanitization: The skill implements a regex-based secret scrubber in hooks/observe.sh to remove API keys and tokens from logs, but it does not perform any sanitization to prevent prompt injection or instruction hijacking from malicious tool outputs.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 31, 2026, 12:12 PM
Security Audit — agent-trust-hub — continuous-learning-v2