skills/othmanadi/apex/apex-learn/Gen Agent Trust Hub

apex-learn

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill implements a self-improvement mechanism where the agent extracts rules from its interactions and persists them into AGENTS.md. Since this file is intended to be read by agents at the start of every task, it functions as a persistent instruction set. An adversary could potentially exploit this by tricking the agent into 'learning' and documenting malicious rules, which would then govern the behavior of all future agents in the project environment.
  • Ingestion points: Agent's friction analysis and task retrospectives as described in SKILL.md (Step 1).
  • Boundary markers: The AGENTS.md file uses section headers, but lacks robust delimiters to prevent instructions from bleeding across contexts or being misinterpreted.
  • Capability inventory: Filesystem write access to AGENTS.md via the scripts in the scripts/ directory.
  • Sanitization: No sanitization or validation is performed on the extracted 'rules' before they are appended to the markdown file.
  • [COMMAND_EXECUTION]: The skill relies on shell (append-learning.sh) and PowerShell (append-learning.ps1) scripts to perform its primary function. While these scripts are limited to local file modification, they provide the agent with a method to programmatically alter project documentation and configuration files.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 12:43 AM
Security Audit — agent-trust-hub — apex-learn