continuous-learning

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill documentation provides instructions for users to manually configure a Stop hook in their ~/.claude/settings.json file. This hook executes the evaluate-session.sh bash script whenever an agent session concludes.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze session transcripts which contain untrusted data from user inputs and external tool outputs. This creates a surface for indirect prompt injection if a transcript contains malicious instructions intended to influence the agent during the pattern extraction phase.
  • Ingestion points: The script evaluate-session.sh identifies and accesses the session chat history via a transcript_path provided by the platform context.
  • Boundary markers: The skill does not employ explicit boundary markers or "ignore instructions" delimiters when requesting the agent to evaluate the transcript content.
  • Capability inventory: The associated shell script is limited to local file system checks, directory creation (mkdir -p), and message counting via grep.
  • Sanitization: No sanitization or filtering is performed on the transcript data before it is presented to the agent for evaluation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:39 PM
Security Audit — agent-trust-hub — continuous-learning