buffett-perspective

Pass

Audited by Gen Agent Trust Hub on Jul 29, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is purely instructional and data-driven, providing a cognitive framework for the agent to simulate a specific persona. It does not include scripts, executables, or commands that interact with the host system.
  • [PROMPT_INJECTION]: The role-playing instructions in SKILL.md are standard and focused on persona consistency. There are no attempts to override agent safety filters or extract system prompts.
  • [EXTERNAL_DOWNLOADS]: The documentation mentions an installation command (npx skills add nuwa-skills/buffett-skill), which is a standard procedure for this platform's ecosystem. The skill itself does not perform any remote code execution or download unverified dependencies at runtime.
  • [DATA_EXFILTRATION]: No sensitive file paths, credential patterns, or network exfiltration patterns were identified. The skill operates within the provided context.
  • [INDIRECT_PROMPT_INJECTION]: While the skill processes user-provided investment queries (Category 8 surface), it lacks the dangerous capabilities (file writing, network access, command execution) required to weaponize such an injection. The risk is assessed as safe.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 29, 2026, 02:19 PM
Security Audit — agent-trust-hub — buffett-perspective