python-packaging-patterns
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references standard Python packaging tools including
hatch,setuptools,flit,poetry,uv, andtwine. These are well-known, industry-standard utilities for managing and publishing Python code. - [CREDENTIALS_UNSAFE]: The documentation includes a template for GitHub Actions using
${{ secrets.PYPI_API_TOKEN }}. This is a secure best practice for secret management in CI/CD pipelines and does not expose actual credentials. - [COMMAND_EXECUTION]: Instructions include standard development commands like
pip install -e .andpython -m build. These are expected operations for the stated purpose of configuring Python environments and packaging projects. - [INDIRECT_PROMPT_INJECTION]: The skill serves as a structural guide and template provider. While it processes developer-provided names and descriptions into project files, it contains no mechanisms for executing instructions embedded in untrusted external data.
Audit Metadata