learn-timeout

Warn

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The file lib/storage.py uses joblib.load() to restore model data. This function uses pickle-based deserialization, which is inherently unsafe and can lead to arbitrary code execution if an attacker manages to modify the .joblib files in the skill's models directory.\n- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from multiple external sources, creating an attack surface for indirect prompt injection.\n
  • Ingestion points: scripts/collect.py gathers training data from EXTRACTOR_CORPUS_DIR, SUPERVISOR_LOGS_DIR, and SUPERVISOR_REPORTS_DIR. lib/sources.py additionally recalls execution metadata from the agent's operational memory client.\n
  • Boundary markers: Absent; data is parsed using regex or JSON loading without delimiters or 'ignore' instructions.\n
  • Capability inventory: The skill can train and save machine learning models to the local filesystem and influence agent behavior via recommended timeout values.\n
  • Sanitization: Absent; data is passed directly into TaskFeatures and feature vectorization without validation or filtering.\n- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill reads from system-wide paths such as /mnt/storage12tb/extractor_corpus and /mnt/storage12tb/supervisor/logs. While these are used for training data collection, it involves accessing logs and reports that may contain sensitive execution metadata. The skill also transmits model summaries to a local memory service at http://127.0.0.1:8601/learn.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 17, 2026, 06:36 AM
Security Audit — agent-trust-hub — learn-timeout