compound-learnings
Warn
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: MEDIUMPERSISTENCEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONPRIVILEGE_ESCALATION
Full Analysis
- [PERSISTENCE]: The skill creates shell scripts in the
.claude/hooks/directory and registers them in the project'ssettings.jsonfile. These hooks are configured to execute automatically when specific events occur (e.g.,SessionEnd,PostToolUse), allowing for code execution to persist across different agent sessions. - [DYNAMIC_EXECUTION]: The skill generates executable shell scripts and TypeScript files at runtime based on patterns extracted from session learnings. It specifically guides the creation of wrapper scripts that pipe data into Node.js processes and modifies the local environment to support these new executables.
- [PRIVILEGE_ESCALATION]: The skill uses the
Bashtool to performchmod +xon newly created shell scripts in the.claude/hooks/directory, granting execution permissions to dynamically generated content. - [COMMAND_EXECUTION]: The process involves executing shell commands to write files, create directories, and modify project configuration files using
catand other basic utilities within theBashtool. - [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect injection as it ingests and processes data that could be influenced by external sources encountered during a session.
- Ingestion points: The skill reads and extracts patterns from markdown files located in
$CLAUDE_PROJECT_DIR/.claude/cache/learnings/*.md. - Boundary markers: The instructions do not define delimiters or "ignore embedded instructions" markers when reading and parsing the learning files.
- Capability inventory: The skill has the capability to write files (
Write,Edit), execute shell commands (Bash), and modify persistent project settings (settings.json). - Sanitization: No explicit sanitization or validation of the content extracted from the learning files is performed before it is interpolated into new rules or executable scripts.
Audit Metadata