continuous-learning
Pass
Audited by Gen Agent Trust Hub on Mar 31, 2026
Risk Level: SAFEDATA_EXFILTRATIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [DATA_EXFILTRATION]: The skill reads session transcripts from the local filesystem to evaluate message counts. These transcripts contain the full history of user interactions with the agent. This data access is a core requirement for the skill's pattern extraction functionality.
- [COMMAND_EXECUTION]: The evaluator script uses standard shell commands to manage its environment and configuration. It executes
mkdir -pto ensure the storage directory for learned skills exists at~/.claude/skills/learned/. - [COMMAND_EXECUTION]: The skill's setup instructions guide the user to add a
Stophook to their global~/.claude/settings.jsonfile. This ensures the evaluation script executes automatically at the end of every agent session. - [PROMPT_INJECTION]: The skill implements an automated learning loop from session history, which serves as a surface for indirect prompt injection. If an attacker influences a session that is subsequently processed and 'learned', malicious instructions could be incorporated into future agent capabilities.
- Ingestion points: Reads session transcripts via the
transcript_pathprovided in the hook's standard input or environment variables. - Boundary markers: The evaluator script does not implement delimiters or instructions to ignore embedded prompts within the processed transcript.
- Capability inventory: The skill allows the agent to trigger pattern extraction and write new executable skill files to the
~/.claude/skills/learned/directory. - Sanitization: No content validation or sanitization of transcript data is performed before signaling the evaluation process.
Audit Metadata