python-pro
Fail
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: CRITICALEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references an external documentation link at https://jeffallan.github.io/claude-skills/skills/language/python-pro/. Automated security scans have identified this URL as malicious and blacklisted.
- [REMOTE_CODE_EXECUTION]: The skill instructs the agent to consult an external blacklisted URL for detailed guidance. This presents a risk of the agent encountering and potentially executing or recommending malicious code patterns hosted on the remote site.
- [INDIRECT_PROMPT_INJECTION]: The skill possesses a broad attack surface as it is designed to analyze and process external Python codebases and project configuration files. Ingestion points: Processes project files, pyproject.toml, and source code during analysis and implementation phases. Boundary markers: No specific boundary markers or instructions to ignore embedded malicious prompts within the processed code are provided. Capability inventory: The skill utilizes pytest for test execution, mypy for type checking, and interacts with the filesystem via pathlib. Sanitization: No sanitization or validation of the processed code content is mentioned before execution in testing or linting environments.
Recommendations
- CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
- AI detected serious security threats
- Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata