learn-rule

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes session history to extract lessons and store them as persistent rules, which is an inherent surface for indirect prompt injection where malicious content could be saved to influence future agent behavior.
  • Ingestion points: Data is pulled from the active conversation history and user triggers (e.g., "remember this") as described in SKILL.md.
  • Boundary markers: The skill uses a structured [LEARN] format to separate captured rules from other context.
  • Capability inventory: The skill is limited to persisting text to internal agent memory (LEARNED section/project memory); no file system writes, network requests, or command executions are present.
  • Sanitization: The skill implements a mandatory human-in-the-loop guardrail, explicitly instructing the agent to wait for user approval before persisting any new rule.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:50 PM
Security Audit — agent-trust-hub — learn-rule