think-fermi-estimation
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists entirely of Markdown documentation, templates, and YAML configuration. No executable scripts, binaries, or active code components are present in the package.
- [DATA_EXFILTRATION]: There are no instructions or patterns that access sensitive files (like .ssh, .aws, or .env), environment variables, or credentials. No network operations or external data exfiltration vectors were identified.
- [REMOTE_CODE_EXECUTION]: The skill does not use package managers, download remote scripts, or employ dynamic execution functions (like eval or exec). It relies purely on the agent's reasoning capabilities.
- [PROMPT_INJECTION]: No malicious injection patterns, DAN-style prompts, or instructions to bypass safety guidelines were found. The content is strictly focused on estimation methodology.
- [OBFUSCATION]: The skill does not contain any Base64-encoded strings, zero-width characters, homoglyphs, or other techniques designed to hide malicious intent.
- [INDIRECT_PROMPT_INJECTION]: While the skill processes user-provided quantities for estimation, it lacks the necessary capabilities (such as network or file-write permissions) to be exploited via data ingestion. The risk surface is negligible.
Audit Metadata