investor-warren-buffett

Pass

Audited by Gen Agent Trust Hub on Aug 20, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user queries to apply financial models, which presents a surface for indirect prompt injection.
  • Ingestion points: User-provided investment questions, such as the example query "AI stocks are ripping and I'm worried about a bubble."
  • Boundary markers: The skill lacks explicit delimiters or instructions to ignore embedded commands within user data.
  • Capability inventory: The skill's capabilities are restricted to reading local markdown files and generating text; it has no access to shell commands, network writing, or sensitive environment variables.
  • Sanitization: No input filtering or escaping mechanisms are specified for the ingested user content.
  • [EXTERNAL_DOWNLOADS]: The skill references various external URLs to provide source documentation for its investment frameworks.
  • Evidence: Links to berkshirehathaway.com, fortune.com, nytimes.com, cnbc.com, and columbia.edu are included in the article-index.md and reference files.
  • Context: These references target official repositories, well-known news organizations, and academic institutions. The links are used to ground analysis in authoritative sources and do not involve runtime code execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 20, 2026, 02:22 PM
Security Audit — agent-trust-hub — investor-warren-buffett