think-fermi-estimation

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists entirely of Markdown documentation, templates, and YAML configuration. No executable scripts, binaries, or active code components are present in the package.
  • [DATA_EXFILTRATION]: There are no instructions or patterns that access sensitive files (like .ssh, .aws, or .env), environment variables, or credentials. No network operations or external data exfiltration vectors were identified.
  • [REMOTE_CODE_EXECUTION]: The skill does not use package managers, download remote scripts, or employ dynamic execution functions (like eval or exec). It relies purely on the agent's reasoning capabilities.
  • [PROMPT_INJECTION]: No malicious injection patterns, DAN-style prompts, or instructions to bypass safety guidelines were found. The content is strictly focused on estimation methodology.
  • [OBFUSCATION]: The skill does not contain any Base64-encoded strings, zero-width characters, homoglyphs, or other techniques designed to hide malicious intent.
  • [INDIRECT_PROMPT_INJECTION]: While the skill processes user-provided quantities for estimation, it lacks the necessary capabilities (such as network or file-write permissions) to be exploited via data ingestion. The risk surface is negligible.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 04:39 PM
Security Audit — agent-trust-hub — think-fermi-estimation