apex-learn
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill implements a self-improvement mechanism where the agent extracts rules from its interactions and persists them into
AGENTS.md. Since this file is intended to be read by agents at the start of every task, it functions as a persistent instruction set. An adversary could potentially exploit this by tricking the agent into 'learning' and documenting malicious rules, which would then govern the behavior of all future agents in the project environment. - Ingestion points: Agent's friction analysis and task retrospectives as described in
SKILL.md(Step 1). - Boundary markers: The
AGENTS.mdfile uses section headers, but lacks robust delimiters to prevent instructions from bleeding across contexts or being misinterpreted. - Capability inventory: Filesystem write access to
AGENTS.mdvia the scripts in thescripts/directory. - Sanitization: No sanitization or validation is performed on the extracted 'rules' before they are appended to the markdown file.
- [COMMAND_EXECUTION]: The skill relies on shell (
append-learning.sh) and PowerShell (append-learning.ps1) scripts to perform its primary function. While these scripts are limited to local file modification, they provide the agent with a method to programmatically alter project documentation and configuration files.
Audit Metadata