Back to skill

Security audit

Bill Ackman Investing Skill

Security checks for vulnerabilities and agentic risk

Overview

This is a text-only investing persona skill with no code execution or persistence, but users should treat its concentrated activist-investing guidance as educational rather than financial or legal advice.

Install only if you want an Ackman-style investing analysis persona. Do not treat its output as financial, legal, tax, regulatory, or investment advice, and be cautious because concentrated positions, short campaigns, proxy contests, lobbying, and public pressure tactics can create major loss and compliance risk. Consider narrowing the triggers if you do not want this style to appear in general finance conversations.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (5)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill presents activist investing, concentrated portfolio construction, proxy contests, and public pressure tactics as an operational framework without a clear warning that this is not financial, legal, or regulatory advice. Users could treat the content as actionable guidance and undertake financially or legally sensitive actions without understanding the substantial risks and compliance obligations involved.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger list contains broad terms such as 'value investing', 'high conviction', 'corporate governance', and 'fee structure' that can match many ordinary finance conversations. This can cause the skill to activate outside its intended scope, steering responses toward concentrated activist-investing tactics in contexts where that framing is inappropriate or risky.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger list contains broad generic phrases like "value investing" and "activist investing" that are not uniquely tied to this specific skill. This can cause unintended invocation during unrelated finance conversations, leading the agent to inject specialized guidance or persona behavior when the user did not request it.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The manifest sets the skill language to "en" with no indication of user opt-in, multilingual support, or justification for an English-only constraint. Under the language/locale policy, a fixed language can be a natural-language policy concern when the skill does not offer a choice or explain why the restriction is necessary.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
79% confidence
Finding

Line L15 states 'Long-time Democrat → 2024 Trump endorser; pro-Israel activist' as part of the skill's defining profile. This embeds a politically specific stance in natural-language content without indicating that users can opt in to or avoid politically loaded framing.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.