buffett
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external, untrusted data such as financial reports and shareholder letters which could contain hidden instructions.
- Ingestion points: Ingestion occurs through the analysis of stock companies, financial reports, annual reports, and shareholder letters mentioned in
SKILL.md. - Boundary markers: The skill does not define boundary markers or explicit instructions for the agent to ignore embedded commands within the processed data.
- Capability inventory: The skill utilizes a
Readtool to access local reference files (references/*.md). It does not demonstrate network exfiltration, arbitrary command execution, or file write capabilities. - Sanitization: No sanitization, filtering, or validation steps for external content were identified in the instructions.
Audit Metadata