cc-skill-continuous-learning

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill evaluates session transcripts which contain untrusted user input to identify learning opportunities. 1. Ingestion points: The file evaluate-session.sh reads the session transcript via the path specified in the CLAUDE_TRANSCRIPT_PATH environment variable. 2. Boundary markers: There are no explicit delimiters or 'ignore' instructions for the transcript content, though the script only processes metadata. 3. Capability inventory: The skill uses basic file system and text processing tools including mkdir, jq, and grep. 4. Sanitization: The script uses grep -c to count message occurrences, which effectively treats the transcript as raw data and prevents the execution of any embedded instructions.
  • [COMMAND_EXECUTION]: The script executes standard shell commands (jq, grep, sed) to manage its local configuration and evaluate session length. These commands are used for legitimate analytical purposes and are scoped to the agent's local environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:19 AM
Security Audit — agent-trust-hub — cc-skill-continuous-learning