learn-timeout
Warn
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The file
lib/storage.pyusesjoblib.load()to restore model data. This function uses pickle-based deserialization, which is inherently unsafe and can lead to arbitrary code execution if an attacker manages to modify the.joblibfiles in the skill's models directory.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from multiple external sources, creating an attack surface for indirect prompt injection.\n - Ingestion points:
scripts/collect.pygathers training data fromEXTRACTOR_CORPUS_DIR,SUPERVISOR_LOGS_DIR, andSUPERVISOR_REPORTS_DIR.lib/sources.pyadditionally recalls execution metadata from the agent's operational memory client.\n - Boundary markers: Absent; data is parsed using regex or JSON loading without delimiters or 'ignore' instructions.\n
- Capability inventory: The skill can train and save machine learning models to the local filesystem and influence agent behavior via recommended timeout values.\n
- Sanitization: Absent; data is passed directly into
TaskFeaturesand feature vectorization without validation or filtering.\n- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill reads from system-wide paths such as/mnt/storage12tb/extractor_corpusand/mnt/storage12tb/supervisor/logs. While these are used for training data collection, it involves accessing logs and reports that may contain sensitive execution metadata. The skill also transmits model summaries to a local memory service athttp://127.0.0.1:8601/learn.
Audit Metadata