buffett-perspective
Pass
Audited by Gen Agent Trust Hub on Jul 29, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is purely instructional and data-driven, providing a cognitive framework for the agent to simulate a specific persona. It does not include scripts, executables, or commands that interact with the host system.
- [PROMPT_INJECTION]: The role-playing instructions in
SKILL.mdare standard and focused on persona consistency. There are no attempts to override agent safety filters or extract system prompts. - [EXTERNAL_DOWNLOADS]: The documentation mentions an installation command (
npx skills add nuwa-skills/buffett-skill), which is a standard procedure for this platform's ecosystem. The skill itself does not perform any remote code execution or download unverified dependencies at runtime. - [DATA_EXFILTRATION]: No sensitive file paths, credential patterns, or network exfiltration patterns were identified. The skill operates within the provided context.
- [INDIRECT_PROMPT_INJECTION]: While the skill processes user-provided investment queries (Category 8 surface), it lacks the dangerous capabilities (file writing, network access, command execution) required to weaponize such an injection. The risk is assessed as safe.
Audit Metadata