continuous-learning

Pass

Audited by Gen Agent Trust Hub on Mar 31, 2026

Risk Level: SAFEDATA_EXFILTRATIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [DATA_EXFILTRATION]: The skill reads session transcripts from the local filesystem to evaluate message counts. These transcripts contain the full history of user interactions with the agent. This data access is a core requirement for the skill's pattern extraction functionality.
  • [COMMAND_EXECUTION]: The evaluator script uses standard shell commands to manage its environment and configuration. It executes mkdir -p to ensure the storage directory for learned skills exists at ~/.claude/skills/learned/.
  • [COMMAND_EXECUTION]: The skill's setup instructions guide the user to add a Stop hook to their global ~/.claude/settings.json file. This ensures the evaluation script executes automatically at the end of every agent session.
  • [PROMPT_INJECTION]: The skill implements an automated learning loop from session history, which serves as a surface for indirect prompt injection. If an attacker influences a session that is subsequently processed and 'learned', malicious instructions could be incorporated into future agent capabilities.
  • Ingestion points: Reads session transcripts via the transcript_path provided in the hook's standard input or environment variables.
  • Boundary markers: The evaluator script does not implement delimiters or instructions to ignore embedded prompts within the processed transcript.
  • Capability inventory: The skill allows the agent to trigger pattern extraction and write new executable skill files to the ~/.claude/skills/learned/ directory.
  • Sanitization: No content validation or sanitization of transcript data is performed before signaling the evaluation process.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 31, 2026, 12:12 PM
Security Audit — agent-trust-hub — continuous-learning