continuous-learning-v2

Warn

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill makes extensive use of subprocesses and shell commands to manage project state and execute the observer agent. Specifically, instinct-cli.py and start-observer.sh use subprocess.run and shell execution to call git and the claude CLI.
  • [EXTERNAL_DOWNLOADS]: The import command in instinct-cli.py uses urllib.request.urlopen to download and parse instinct files from arbitrary remote URLs provided by the user.
  • [DATA_EXFILTRATION]: The observe.sh hook captures all tool inputs and outputs during active sessions, logging them to a local observations.jsonl file. While the script includes a _SECRET_RE regex to redact common patterns for API keys, tokens, and passwords, the broad capture of session data represents a potential exposure risk for sensitive information not caught by the filter.
  • [PROMPT_INJECTION]: The background observer agent (Haiku) reads session logs to identify patterns and create new instruction files. This creates a surface for Indirect Prompt Injection, where malicious content ingested by tools (e.g., via Curl or Edit on untrusted sources) could influence the agent to generate harmful or deceptive instincts that override future behavior.
  • Ingestion points: observations.jsonl (monitored by observer-loop.sh).
  • Boundary markers: Absent in the observer's prompt logic; it treats log content as raw data for pattern detection.
  • Capability inventory: Read and Write file access (authorized via the observer.md agent definition and the claude CLI call).
  • Sanitization: Secret redaction is implemented via regex, but no sanitization is performed to prevent instruction injection from the logs into the sub-agent.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Apr 11, 2026, 03:42 AM
Security Audit — agent-trust-hub — continuous-learning-v2