dojo-charlie-munger

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [NO_CODE]: The skill is entirely composed of documentation and instructional Markdown files. It includes no executable scripts, source code, or binary artifacts, which significantly limits the potential for technical exploitation.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes user queries to provide expert advice, creating an inherent surface for indirect prompt injection attacks. However, the risk is negligible due to the restricted environment.\n
  • Ingestion points: Untrusted user questions are processed by the agent to determine routing and persona voice, as instructed in SKILL.md.\n
  • Boundary markers: There are no explicit delimiters used to separate user data from the core instructions within the skill files.\n
  • Capability inventory: The skill is passive and informational; it does not possess tools for network access, file system modification, or command execution. The agent is limited to text generation based on the provided topic files.\n
  • Sanitization: User input is not sanitized or filtered, but the lack of executable capabilities ensures no high-severity risk is present.\n- [SAFE]: No malicious behavior, data exfiltration patterns, or prompt injections aimed at bypassing safety filters were detected. The skill follows best practices for persona-based information retrieval.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 03:32 PM
Security Audit — agent-trust-hub — dojo-charlie-munger