skills/ericrisco/rsc-harness/python/Gen Agent Trust Hub

python

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a comprehensive instructional guide for Python development best practices, focusing on modern language features and tooling without introducing malicious patterns.- [DYNAMIC_EXECUTION]: The static analysis flag regarding eval usage is a false positive. The skill explicitly labels eval(user_input) and exec() as dangerous 'anti-patterns' in SKILL.md and provides ast.literal_eval() as the secure alternative for handling untrusted data.- [EXTERNAL_DOWNLOADS]: The skill uses the uv package manager to synchronize dependencies via uv sync --frozen. This is a standard project management workflow and targets well-known development tools.- [COMMAND_EXECUTION]: The provided verify.sh script automates the execution of established quality assurance tools including ruff, mypy, and pytest. These operations are restricted to the local development environment and align with the skill's purpose as a quality gate.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 08:57 AM
Security Audit — agent-trust-hub — python