continuous-learning
Fail
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: HIGHPERSISTENCEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [PERSISTENCE]: The skill's documentation instructs the user to modify the global
~/.claude/settings.jsonconfiguration file to register aStophook. This hook triggers theevaluate-session.shscript automatically at the conclusion of every agent session, ensuring the script remains active and runs persistently across all future interactions. - [INDIRECT_PROMPT_INJECTION]: The skill creates a significant attack surface by ingesting the full session transcript via the
CLAUDE_TRANSCRIPT_PATHenvironment variable. The script signals the agent to evaluate this untrusted content for pattern extraction without providing sanitization or boundary markers. - Ingestion points: Reads the current session transcript from the path defined in
CLAUDE_TRANSCRIPT_PATH(referenced inevaluate-session.sh). - Boundary markers: None. The script directly prints a message to the agent context asking it to "evaluate for extractable patterns" without using delimiters or instructions to ignore embedded commands.
- Capability inventory: The agent is empowered to generate and save new skill files to
~/.claude/skills/learned/. - Sanitization: No filtering or sanitization of the transcript content is performed before the agent is asked to process it.
- [DYNAMIC_EXECUTION]: The core functionality involves the agent generating new markdown skills containing executable instructions. Because these instructions are derived from untrusted session data, an attacker could theoretically poison a conversation to trick the agent into saving a malicious skill that would then be executed in future sessions.
- [COMMAND_EXECUTION]: The skill utilizes a shell script (
evaluate-session.sh) to perform environment checks and signal the agent. It uses thejqutility to parse local configuration files.
Recommendations
- AI detected serious security threats
Audit Metadata