The Essays Of Warren Buffett

Security checks across malware telemetry and agentic risk

Overview

This is a text-only educational Buffett investing skill with no executable code, credential access, persistence, or hidden data movement.

Installers should treat this as educational commentary, not personalized investment advice. Be aware it may activate on broad Buffett or value-investing prompts and it requires a Heardly promotional footer in responses.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
94% confidence
Finding
The trigger list is unusually broad and includes generic finance and onboarding phrases such as 'Value investing' and activating when a user 'doesn't know how to start.' This can cause unintended invocation in unrelated conversations, creating prompt hijacking surface area, confusing routing, and unnecessary exposure of the skill's instructions and behavioral constraints.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal