continuous-learning
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill implements a mechanism to extract patterns from coding sessions and user corrections, storing them in memory files like
CLAUDE.mdorLEARNED.md. These files serve as persistent context for the agent in future interactions. An attacker could provide malicious code or deceptive 'corrections' that the agent then extracts as 'high-confidence' patterns, effectively poisoning its future behavior. - Ingestion points: The skill instructs the agent to 'Review changes made', 'Identify corrections', and 'Note successful first-attempts' from coding sessions (found in
SKILL.md). - Boundary markers: There are no specified boundary markers or 'ignore' instructions for the data written to the knowledge base files to prevent the LLM from executing instructions hidden within the stored patterns.
- Capability inventory: The agent has the capability to write to local project files (
CLAUDE.md,LEARNED.md,knowledge/*.md) and is instructed to 'Apply automatically' patterns with a confidence score above 0.95. - Sanitization: The instructions lack any requirement for sanitizing or validating the extracted patterns before they are promoted to established project conventions.
Audit Metadata