Self Learning Agent

Security checks across static analysis, malware telemetry, and agentic risk

Overview

This is a transparent local memory-card workflow, but it can automatically save and reuse personal, project, and infrastructure details across sessions.

This skill appears coherent and instruction-only. Install it if you want a local persistent memory workflow, but treat the memory directory like sensitive notes: review it, keep it out of public repositories, and do not store secrets or private details unless you are comfortable with future agent sessions seeing them.

Static analysis

No static analysis findings were reported for this release.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Risk analysis

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

The agent may remember and later rely on details you did not explicitly ask it to save, including sensitive project or personal context.

Why it was flagged

The skill intentionally creates persistent memory that may store personal, project, or infrastructure facts without a separate prompt each time. This is aligned with the memory purpose, but retained or inaccurate cards could be reused in later sessions.

Skill content
"Automatic (agent should capture without being asked)" ... "User corrections" ... "Non-obvious facts about infrastructure, people, or projects"
Recommendation

Use this only in trusted workspaces, review cards and logs periodically, and avoid saving passwords, tokens, private personal data, or sensitive infrastructure details unless you intentionally want them retained.