continuous-learning

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests session transcripts to extract reusable patterns and save them as new skills.
  • Ingestion points: The script evaluate-session.sh identifies the session transcript path from the agent's hook input.
  • Boundary markers: The skill lacks explicit instructions for the agent to ignore or sanitize embedded malicious instructions within the transcript during the extraction process.
  • Capability inventory: The system has the capability to write new skill files to ~/.claude/skills/learned/ based on analyzed session data.
  • Sanitization: No sanitization or validation of the 'learned' content is described, allowing potentially malicious patterns to be persisted into the agent's long-term configuration.
  • [COMMAND_EXECUTION]: The skill instructions guide the user to modify ~/.claude/settings.json to execute a shell script (evaluate-session.sh) as a 'Stop' hook. While this is the intended functionality for session persistence, it involves executing local shell commands every time a session terminates.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 03:23 AM
Security Audit — agent-trust-hub — continuous-learning