estimate-actual

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill implements a robust estimation calibration workflow using standard repository analysis tools and does not contain any malicious code or exfiltration patterns.
  • [COMMAND_EXECUTION]: The skill utilizes local tools like git, gh, grep, and a project-specific python script (code_graph) for static analysis of the codebase. These operations are scoped to the project environment and are used for counting and classifying files and lines.
  • [DATA_EXFILTRATION]: No network operations to external or untrusted domains were detected. Data is processed locally and results are persisted to a local CSV file (plans/_estimation-samples.csv).
  • [PROMPT_INJECTION]: The instructions include operational directives related to subagent authorization and execution contracts. These are intended for agent orchestration within platform guidelines and do not attempt to bypass safety filters.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 08:23 PM
Security Audit — agent-trust-hub — estimate-actual