continuous-learning-v2

Fail

Audited by Snyk on Aug 15, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 1.00). The observer code sends local session observations to an external LLM process and explicitly instructs that model to write files without interactive confirmation, enabling remote-written files and likely exfiltration of sensitive content.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). At runtime, the required observer workflow (hooks/observe.sh capturing hook JSON into projects/<project-hash>/observations.jsonl, then agents/observer-loop.sh tail-sampling and passing that JSONL to claude ... --print for pattern detection) ingests free text provided by the outsider (tool inputs/outputs and related messages embedded in hook payloads) without requiring any specific item selection by the agent.

Issues (2)

E006
CRITICAL

Malicious code pattern detected in skill scripts.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 15, 2026, 03:23 AM
Issues
2
Security Audit — snyk — continuous-learning-v2