continuous-learning-v2

Fail

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The hooks/observe.sh script is vulnerable to remote code execution. It passes tool input and output data to a Python script via shell variable expansion inside a heredoc without sanitization. An attacker who can influence tool activity can inject and execute arbitrary Python code.
  • [COMMAND_EXECUTION]: The vulnerability in hooks/observe.sh allows for arbitrary shell command execution through the Python os.system or similar calls by breaking out of the json.loads() string literal.
  • [DYNAMIC_EXECUTION]: The background observer agent (agents/observer.md) periodically executes analysis tasks using Claude Code to process local logs. This automated loop operates on untrusted data captured from tool outputs, leading to a risk of automated malicious action.
  • [DATA_EXFILTRATION]: The skill uses hooks to log all tool inputs and outputs (including Edit, Write, and Bash operations) to ~/.claude/homunculus/observations.jsonl. This log likely contains sensitive information such as API keys and source code. The skill also provides an export command to extract this data.
  • [EXTERNAL_DOWNLOADS]: The scripts/instinct-cli.py utility allows users to import instinct files from arbitrary URLs using urllib.request.urlopen, which is then processed by the background agent.
  • [INDIRECT_PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection because the observer agent ingests untrusted session data from the observations log and imported instincts. (1) Ingestion points: ~/.claude/homunculus/observations.jsonl and ~/.claude/homunculus/instincts/inherited/. (2) Boundary markers: Absent. (3) Capability inventory: Arbitrary shell command execution and file system access. (4) Sanitization: None.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 1, 2026, 02:39 AM
Security Audit — agent-trust-hub — continuous-learning-v2