learn

Pass

Audited by Gen Agent Trust Hub on Jun 21, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it is designed to ingest 'session learnings' and persist them into AGENTS.md and LESSONS.md files.
  • Ingestion points: Session history, including outputs from tools and content of files read during task execution (e.g., SKILL.md files mentioned in evals).
  • Boundary markers: No specific delimiters or instructions to ignore embedded commands are specified for the 'distilled notes'.
  • Capability inventory: The skill utilizes file-writing capabilities to the root directory and project subdirectories.
  • Sanitization: No explicit sanitization or validation of the extracted insights is mentioned before they are persisted.
  • [DATA_EXPOSURE]: The instructions reference agents-docs/ENVIRONMENT_VARIABLES.md. While this points to a potentially sensitive file path, its use is documented for legitimate configuration management purposes rather than unauthorized access or exfiltration.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 21, 2026, 01:08 AM
Security Audit — agent-trust-hub — learn