continuous-learning-v2
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPERSISTENCEDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The observer agent processes session logs containing untrusted data (tool inputs and outputs) to detect patterns and generate instincts. The following evidence chain is identified:
- Ingestion points:
agents/observer-loop.shreads session logs fromobservations.jsonl(generated byhooks/observe.sh). - Boundary markers: Absent within the log data; the agent relies on system instructions in
agents/observer-loop.shto distinguish data from instructions. - Capability inventory: The observer agent has access to
ReadandWritetools, allowing it to modify files within theinstincts/personaldirectory. - Sanitization:
hooks/observe.shredacts common secret patterns using regular expressions and truncates tool input/output to 5000 characters to mitigate large-scale data injection. - [EXTERNAL_DOWNLOADS]: The
instinct-cli.pyscript allows importing behavioral instincts from remote HTTPS URLs via the/instinct-importcommand. - The implementation includes a
_validate_import_urlfunction that enforces HTTPS and performs DNS resolution checks to ensure the target host is a public IP, mitigating Server-Side Request Forgery (SSRF) risks. - [COMMAND_EXECUTION]: The skill uses shell scripts and the Python
subprocessmodule to interact with the local environment,git, and the platform CLI. - Key execution points include project detection logic in
scripts/detect-project.sh, background process management inagents/start-observer.sh, and observation capture inhooks/observe.sh. - [PERSISTENCE]: The skill maintains persistence through background execution and session hooks.
- The observer agent is launched as a background process using
nohupinagents/start-observer.sh. - Learning hooks in
hooks/observe.share registered with the agent platform to trigger on every tool use event across sessions. - [DATA_EXFILTRATION]: The system records detailed logs of tool interactions, including inputs and outputs, which could potentially include sensitive information if secret scrubbing fails.
- The
/instinct-exportcommand inscripts/instinct-cli.pyallows these learned patterns to be written to arbitrary files on the local system, subject to path validation that prevents writing to sensitive system directories.
Audit Metadata