cc-skill-continuous-learning
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONPERSISTENCE
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes a bash script
evaluate-session.shdesigned to be executed by the agent's shell hook system. This script processes conversation transcripts and interacts with the local filesystem. - [INDIRECT_PROMPT_INJECTION]: The core functionality involves the agent analyzing conversation transcripts (which contain untrusted user input) to generate new skill files in
~/.claude/skills/learned/. If an attacker provides malicious instructions disguised as a 'novel debugging technique' or 'workaround', the agent may inadvertently codify these into a new skill, leading to persistent malicious behavior. - [PERSISTENCE]: The skill's documentation specifically instructs the user to modify
~/.claude/settings.jsonto register aStophook. This ensures the analysis script runs automatically at the end of every session, providing a persistent execution trigger.
Audit Metadata