continuous-learning-v2

Pass

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill makes extensive use of subprocess.run and shell scripts to manage background observer processes, perform git operations for project identification, and trigger autonomous analysis using the claude CLI.
  • [EXTERNAL_DOWNLOADS]: The instinct-cli.py script enables the downloading of 'instinct' instruction files from user-specified remote URLs via urllib.request, which are then integrated into the agent's persistent behavior profile.
  • [PROMPT_INJECTION]: The skill features a vulnerability to indirect prompt injection. The background observer agent processes tool outputs—which may include data from untrusted websites or files—and converts observed patterns into persistent instructions. This could allow external data to poison the agent's long-term behavior.
  • [DATA_EXFILTRATION]: The skill continuously records tool inputs and outputs into local observations.jsonl files. Although it employs a regular-expression-based scrubber to remove potential credentials, the storage of comprehensive session history creates a significant local data exposure surface.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 17, 2026, 01:13 PM