continuous-learning

Warn

Audited by Socket on Mar 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose matches session learning, but the mechanism is high-risk because it turns untrusted transcript content into persistent skills that can influence future agent behavior. No clear credential theft or external exfiltration is present, but the automatic hook plus skill-generation workflow creates meaningful prompt-injection and persistence risk.

Confidence: 87%Severity: 72%
Audit Metadata
Analyzed At
Mar 31, 2026, 02:06 AM
Package URL
pkg:socket/skills-sh/zzafergok%2Fskills%2Fcontinuous-learning%2F@d52862dd97e63c119eee837247cb10a590a492ab
Security Audit — socket — continuous-learning