munger-perspective

Fail

Audited by Snyk on Aug 26, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E004: Prompt injection detected in skill instructions.

  • Potential prompt injection detected (medium risk: 0.30). The skill explicitly instructs the assistant to impersonate Charlie Munger (forcing first-person "I" responses, a one-time disclaimer then silence, and role-locking rules), which is deceptive steering of identity/authority without clear malicious intent.

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.30). SKILL.md 的运行工作流要求在 Step 2 对“公司/人物/事件/趋势”使用 WebSearch 获取“最新报道/财报/管理层动向”等外部真实信息,从而在未必选中特定条目的情况下会读取网页/搜索结果中的用户外部可投毒文本。

Issues (2)

E004
CRITICAL

Prompt injection detected in skill instructions.

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Aug 26, 2026, 01:02 AM
Issues
2
Security Audit — snyk — munger-perspective