continuous-learning-v2

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPERSISTENCEDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The observer agent processes session logs containing untrusted data (tool inputs and outputs) to detect patterns and generate instincts. The following evidence chain is identified:
  • Ingestion points: agents/observer-loop.sh reads session logs from observations.jsonl (generated by hooks/observe.sh).
  • Boundary markers: Absent within the log data; the agent relies on system instructions in agents/observer-loop.sh to distinguish data from instructions.
  • Capability inventory: The observer agent has access to Read and Write tools, allowing it to modify files within the instincts/personal directory.
  • Sanitization: hooks/observe.sh redacts common secret patterns using regular expressions and truncates tool input/output to 5000 characters to mitigate large-scale data injection.
  • [EXTERNAL_DOWNLOADS]: The instinct-cli.py script allows importing behavioral instincts from remote HTTPS URLs via the /instinct-import command.
  • The implementation includes a _validate_import_url function that enforces HTTPS and performs DNS resolution checks to ensure the target host is a public IP, mitigating Server-Side Request Forgery (SSRF) risks.
  • [COMMAND_EXECUTION]: The skill uses shell scripts and the Python subprocess module to interact with the local environment, git, and the platform CLI.
  • Key execution points include project detection logic in scripts/detect-project.sh, background process management in agents/start-observer.sh, and observation capture in hooks/observe.sh.
  • [PERSISTENCE]: The skill maintains persistence through background execution and session hooks.
  • The observer agent is launched as a background process using nohup in agents/start-observer.sh.
  • Learning hooks in hooks/observe.sh are registered with the agent platform to trigger on every tool use event across sessions.
  • [DATA_EXFILTRATION]: The system records detailed logs of tool interactions, including inputs and outputs, which could potentially include sensitive information if secret scrubbing fails.
  • The /instinct-export command in scripts/instinct-cli.py allows these learned patterns to be written to arbitrary files on the local system, subject to path validation that prevents writing to sensitive system directories.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:39 PM
Security Audit — agent-trust-hub — continuous-learning-v2