python-packaging-patterns

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references standard Python packaging tools including hatch, setuptools, flit, poetry, uv, and twine. These are well-known, industry-standard utilities for managing and publishing Python code.
  • [CREDENTIALS_UNSAFE]: The documentation includes a template for GitHub Actions using ${{ secrets.PYPI_API_TOKEN }}. This is a secure best practice for secret management in CI/CD pipelines and does not expose actual credentials.
  • [COMMAND_EXECUTION]: Instructions include standard development commands like pip install -e . and python -m build. These are expected operations for the stated purpose of configuring Python environments and packaging projects.
  • [INDIRECT_PROMPT_INJECTION]: The skill serves as a structural guide and template provider. While it processes developer-provided names and descriptions into project files, it contains no mechanisms for executing instructions embedded in untrusted external data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 06:52 PM
Security Audit — agent-trust-hub — python-packaging-patterns