continuous-learning
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill documentation provides instructions for users to manually configure a
Stophook in their~/.claude/settings.jsonfile. This hook executes theevaluate-session.shbash script whenever an agent session concludes. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze session transcripts which contain untrusted data from user inputs and external tool outputs. This creates a surface for indirect prompt injection if a transcript contains malicious instructions intended to influence the agent during the pattern extraction phase.
- Ingestion points: The script
evaluate-session.shidentifies and accesses the session chat history via atranscript_pathprovided by the platform context. - Boundary markers: The skill does not employ explicit boundary markers or "ignore instructions" delimiters when requesting the agent to evaluate the transcript content.
- Capability inventory: The associated shell script is limited to local file system checks, directory creation (
mkdir -p), and message counting viagrep. - Sanitization: No sanitization or filtering is performed on the transcript data before it is presented to the agent for evaluation.
Audit Metadata