continuous-learning-v2

Warn

Audited by Socket on Aug 15, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
agents/observer-loop.sh

No clear evidence of classic malware (reverse shell, crypto-mining, destructive file ops, credential theft, or obfuscated payloads) is present in the provided fragment. The main security concern is supply-chain-style information disclosure: the script reads a local prompt file and passes it to an external "claude" process/tool with "Read,Write" enabled, and archives resulting observations. Whether this is malicious depends on the surrounding code—especially what content is placed into "$prompt_file" and whether claude’s endpoint/tooling is trusted and properly authenticated. Verify prompt/observation contents for secrets and confirm external telemetry/exfiltration policies.

Confidence: 62%Severity: 55%
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill’s core behavior matches its stated purpose, and install provenance appears same-org, but it uses wildcard hooks to capture all tool activity and prompts, stores detailed observations, and describes background model analysis in a way that conflicts with its privacy claims. This looks like an overbroad local telemetry/learning system rather than malware, with moderate security and privacy risk.

Confidence: 82%Severity: 58%
Audit Metadata
Analyzed At
Aug 15, 2026, 03:25 AM
Package URL
pkg:socket/skills-sh/khanhhuyenngo985-sys%2Fcharacter-scene-design-skills%2Fcontinuous-learning-v2%2F@ec1e77d58e01a10ef77080a5ff55a18fd0396df5dd826b488fd89c7c52938097
Security Audit — socket — continuous-learning-v2