replay-learnings

Warn

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill's workflow instructs the agent to execute grep commands using keywords extracted from user-provided task descriptions. This interpolation of user input into a shell command string without explicit sanitization guidelines represents a potential command injection risk if a user provides input containing shell metacharacters (e.g., semicolons, backticks, or pipe symbols).
  • [INDIRECT_PROMPT_INJECTION]: The skill reads from local files that serve as a memory for the agent, which could contain untrusted content or instructions that influence the agent's behavior during the 'replay' phase.
  • Ingestion points: The skill reads from .claude/LEARNED.md, .claude/learning-log.md, and CLAUDE.md as specified in SKILL.md.
  • Boundary markers: There are no delimiters or instructions to ignore embedded commands within the retrieved text to prevent the agent from following instructions found inside the logs.
  • Capability inventory: The agent uses shell commands (grep) to search and display the content of these files.
  • Sanitization: No sanitization of search keywords or filtering of retrieved content is described in the workflow.
  • [DATA_EXFILTRATION]: The skill accesses project-specific metadata and history files in the .claude/ directory. While used for legitimate session recall, these files could contain sensitive information from previous sessions that might be exposed to the current context if it matches the search keywords.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 14, 2026, 07:50 PM
Security Audit — agent-trust-hub — replay-learnings