investor-warren-buffett
Pass
Audited by Gen Agent Trust Hub on Aug 20, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user queries to apply financial models, which presents a surface for indirect prompt injection.
- Ingestion points: User-provided investment questions, such as the example query "AI stocks are ripping and I'm worried about a bubble."
- Boundary markers: The skill lacks explicit delimiters or instructions to ignore embedded commands within user data.
- Capability inventory: The skill's capabilities are restricted to reading local markdown files and generating text; it has no access to shell commands, network writing, or sensitive environment variables.
- Sanitization: No input filtering or escaping mechanisms are specified for the ingested user content.
- [EXTERNAL_DOWNLOADS]: The skill references various external URLs to provide source documentation for its investment frameworks.
- Evidence: Links to
berkshirehathaway.com,fortune.com,nytimes.com,cnbc.com, andcolumbia.eduare included in thearticle-index.mdand reference files. - Context: These references target official repositories, well-known news organizations, and academic institutions. The links are used to ground analysis in authoritative sources and do not involve runtime code execution.
Audit Metadata