continuous-learning-v2
Fail
Audited by Snyk on Aug 15, 2026
Risk Level: CRITICAL
Full Analysis
CRITICAL E006: Malicious code pattern detected in skill scripts.
- Malicious code pattern detected (high risk: 1.00). The observer code sends local session observations to an external LLM process and explicitly instructs that model to write files without interactive confirmation, enabling remote-written files and likely exfiltration of sensitive content.
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (medium risk: 0.30). At runtime, the required observer workflow (
hooks/observe.shcapturing hook JSON intoprojects/<project-hash>/observations.jsonl, thenagents/observer-loop.shtail-sampling and passing that JSONL toclaude ... --printfor pattern detection) ingests free text provided by the outsider (tool inputs/outputs and related messages embedded in hook payloads) without requiring any specific item selection by the agent.
Issues (2)
E006
CRITICALMalicious code pattern detected in skill scripts.
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata