Back to skill

Security audit

Charlie Munger Investing Skill

Security checks across malware telemetry and agentic risk

Overview

This is a text-only Charlie Munger investing and mental-models skill with no code execution, credential access, persistence, or hidden data handling.

Install only if you want a Charlie Munger-style educational reasoning lens. Be aware it may activate on generic phrases, and do not treat its investing content as financial, tax, or legal advice.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger list contains several generic phrases such as "mental models," "inversion," "rationality," and "patience in investing" that could match ordinary user queries and invoke the skill unintentionally. This does not appear malicious, but overly broad activation can cause prompt-routing errors, unexpected persona takeover, or irrelevant investment-flavored guidance in contexts where the user did not request it.

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger list contains several generic phrases such as "mental models," "inversion," and "multidisciplinary thinking" that are common in ordinary conversation and not uniquely tied to this skill. In systems that auto-invoke skills from trigger matches, this can cause unintended activation, irrelevant context injection, or prompt-routing mistakes that may interfere with user intent and increase the attack surface for prompt manipulation.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.