continuous-learning-v2
Warn
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill makes extensive use of subprocesses and shell commands to manage project state and execute the observer agent. Specifically,
instinct-cli.pyandstart-observer.shusesubprocess.runand shell execution to callgitand theclaudeCLI. - [EXTERNAL_DOWNLOADS]: The
importcommand ininstinct-cli.pyusesurllib.request.urlopento download and parse instinct files from arbitrary remote URLs provided by the user. - [DATA_EXFILTRATION]: The
observe.shhook captures all tool inputs and outputs during active sessions, logging them to a localobservations.jsonlfile. While the script includes a_SECRET_REregex to redact common patterns for API keys, tokens, and passwords, the broad capture of session data represents a potential exposure risk for sensitive information not caught by the filter. - [PROMPT_INJECTION]: The background observer agent (Haiku) reads session logs to identify patterns and create new instruction files. This creates a surface for Indirect Prompt Injection, where malicious content ingested by tools (e.g., via
CurlorEditon untrusted sources) could influence the agent to generate harmful or deceptive instincts that override future behavior. - Ingestion points:
observations.jsonl(monitored byobserver-loop.sh). - Boundary markers: Absent in the observer's prompt logic; it treats log content as raw data for pattern detection.
- Capability inventory:
ReadandWritefile access (authorized via theobserver.mdagent definition and theclaudeCLI call). - Sanitization: Secret redaction is implemented via regex, but no sanitization is performed to prevent instruction injection from the logs into the sub-agent.
Audit Metadata