python-pro
Pass
Audited by Gen Agent Trust Hub on Jul 9, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill functions as a technical reference guide for Python programming, providing standard templates and best practices. All included code snippets are benign and intended for educational purposes.
- [SAFE]: All external libraries and tools referenced (e.g., httpx, pydantic, pytest, ruff, poetry) are industry-standard, well-known, and widely trusted within the Python ecosystem.
- [SAFE]: The skill includes explicit 'MUST NOT' constraints that prevent common security pitfalls, such as hardcoding credentials or configuration.
- [PROMPT_INJECTION]: The skill has an attack surface for Indirect Prompt Injection (Category 8) as it is designed to analyze and process external codebases.
- Ingestion points: The agent is instructed to review and analyze structure, dependencies, and code in user-provided projects (SKILL.md).
- Boundary markers: Absent. There are no instructions to use delimiters or ignore instructions potentially embedded in the processed code.
- Capability inventory: The skill allows for file reading, code generation, and execution of CLI tools including pytest, mypy, and ruff (SKILL.md).
- Sanitization: Absent. The skill does not provide methods for escaping or validating the content of the files it processes.
Audit Metadata