munger-perspective

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill defines a set of "EXIT TRIGGER" keywords that allow the user to override the active persona and force the agent to revert to its standard operating mode. It also establishes "Role Play Rules" that constrain agent behavior by prohibiting meta-analysis or character-breaking.
  • [INDIRECT_PROMPT_INJECTION]: The skill implements a workflow that requires the ingestion and processing of untrusted data from external websites.
  • Ingestion points: The SKILL.md instructions include a "芒格式研究" (Munger-style research) phase where the agent is directed to use WebSearch to gather data on companies, executives, and news events.
  • Boundary markers: There are no instructions provided for using delimiters or boundary markers to isolate external content from the skill's logic.
  • Capability inventory: The agent is expected to perform research using external tools and synthesize findings into a judgment.
  • Sanitization: No sanitization or content validation steps are mentioned for the data retrieved via the search tool.
  • [REMOTE_CODE_EXECUTION]: The README.md documentation recommends installation via npx skills add alchaincyf/munger-skill, which involves the execution of a remote package to install skill components from the author's GitHub repository. The installation tool is maintained by a well-known organization.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 01:02 AM
Security Audit — agent-trust-hub — munger-perspective