init-learning

Pass

Audited by Gen Agent Trust Hub on Apr 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill manages local application data at ~/.claude/learning/profile.md. This is standard behavior for profile configuration and does not involve accessing sensitive system credentials or unauthorized file paths.
  • [PROMPT_INJECTION]: The skill identifies a potential surface for indirect prompt injection via the processing of user-pasted feedback in Step 8 of SKILL.md. Ingestion Point: User feedback pasted in the optional final step of profile setup. Boundary markers: None. Capability inventory: File-write to profile.md. Sanitization: The skill implements a manual security control by instructing the agent to extract key themes and present them to the user for confirmation before any data is written to the profile file.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 22, 2026, 03:20 PM