continuous-learning

Warn

Audited by Socket on Mar 13, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the stated purpose matches local transcript analysis and learned-skill persistence, and the hook mechanism/path are official. However, the unseen auto-running shell script processes untrusted session content and writes persistent instructions, creating medium risk of prompt-injection-driven persistence and unreviewed autonomous changes even without clear evidence of credential theft or external exfiltration.

Confidence: 84%Severity: 61%
Audit Metadata
Analyzed At
Mar 13, 2026, 12:39 AM
Package URL
pkg:socket/skills-sh/xu-xiang%2Feverything-claude-code-zh%2Fcontinuous-learning%2F@4049150605b698a8fd7f997afe6d19f135282b9d