python-pro

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill operates on user-provided source code to perform linting, type checking, and testing. This ingestion of external data is the intended primary function of the skill and follows standard development workflows.
  • Ingestion points: User-supplied Python source code and pyproject.toml configuration files as seen in the Core Workflow (SKILL.md).
  • Boundary markers: The skill relies on standard command-line tool boundaries for mypy, ruff, and pytest.
  • Capability inventory: Local execution of linters (ruff, black), type checkers (mypy), and test runners (pytest) as specified in the Output Templates (SKILL.md).
  • Sanitization: The skill expects code to be handled by standard Python development toolchains.
  • [EXTERNAL_DOWNLOADS]: The documentation and code examples reference well-known and widely trusted libraries from the Python ecosystem, such as httpx for asynchronous requests and Pydantic for data validation. These represent standard, legitimate dependencies.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 09:18 PM
Security Audit — agent-trust-hub — python-pro