continuous-learning-v2
Pass
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: The skill makes extensive use of
subprocess.runand shell scripts to manage background observer processes, perform git operations for project identification, and trigger autonomous analysis using theclaudeCLI. - [EXTERNAL_DOWNLOADS]: The
instinct-cli.pyscript enables the downloading of 'instinct' instruction files from user-specified remote URLs viaurllib.request, which are then integrated into the agent's persistent behavior profile. - [PROMPT_INJECTION]: The skill features a vulnerability to indirect prompt injection. The background observer agent processes tool outputs—which may include data from untrusted websites or files—and converts observed patterns into persistent instructions. This could allow external data to poison the agent's long-term behavior.
- [DATA_EXFILTRATION]: The skill continuously records tool inputs and outputs into local
observations.jsonlfiles. Although it employs a regular-expression-based scrubber to remove potential credentials, the storage of comprehensive session history creates a significant local data exposure surface.
Audit Metadata