cc-skill-continuous-learning

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONPERSISTENCE
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes a bash script evaluate-session.sh designed to be executed by the agent's shell hook system. This script processes conversation transcripts and interacts with the local filesystem.
  • [INDIRECT_PROMPT_INJECTION]: The core functionality involves the agent analyzing conversation transcripts (which contain untrusted user input) to generate new skill files in ~/.claude/skills/learned/. If an attacker provides malicious instructions disguised as a 'novel debugging technique' or 'workaround', the agent may inadvertently codify these into a new skill, leading to persistent malicious behavior.
  • [PERSISTENCE]: The skill's documentation specifically instructs the user to modify ~/.claude/settings.json to register a Stop hook. This ensures the analysis script runs automatically at the end of every session, providing a persistent execution trigger.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 06:47 AM