python-pro

Fail

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: CRITICALEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references an external documentation link at https://jeffallan.github.io/claude-skills/skills/language/python-pro/. Automated security scans have identified this URL as malicious and blacklisted.
  • [REMOTE_CODE_EXECUTION]: The skill instructs the agent to consult an external blacklisted URL for detailed guidance. This presents a risk of the agent encountering and potentially executing or recommending malicious code patterns hosted on the remote site.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a broad attack surface as it is designed to analyze and process external Python codebases and project configuration files. Ingestion points: Processes project files, pyproject.toml, and source code during analysis and implementation phases. Boundary markers: No specific boundary markers or instructions to ignore embedded malicious prompts within the processed code are provided. Capability inventory: The skill utilizes pytest for test execution, mypy for type checking, and interacts with the filesystem via pathlib. Sanitization: No sanitization or validation of the processed code content is mentioned before execution in testing or linting environments.
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
  • AI detected serious security threats
  • Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 6, 2026, 11:36 AM
Security Audit — agent-trust-hub — python-pro