wk-workstyle-python

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill defines rules for Python style enforcement (PEP 484, f-strings) and prioritizes project configuration. No behavior override or safety bypass patterns were identified.
  • [DATA_EXFILTRATION]: No sensitive file access or network exfiltration patterns were detected. The tool usage is limited to standard file operations (Read, Glob, Grep).
  • [REMOTE_CODE_EXECUTION]: The skill references standard tools (ruff, black, mypy) and internal commands (wk-learn) without providing instructions for remote script downloads or piped shell execution.
  • [PROMPT_INJECTION]: Indirect Prompt Injection surface analysis: (1) Ingestion points: Agent-controlled .py files; (2) Boundary markers: Not explicitly defined; (3) Capability inventory: Read, Glob, Grep; (4) Sanitization: Not applicable, as the skill performs style enforcement rather than execution of data content.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 09:51 PM
Security Audit — agent-trust-hub — wk-workstyle-python