align-recipe-pyproject
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFE
Full Analysis
- [Code/Dependency Analysis]: The skill uses Python scripts to read and manipulate configuration formats via standard, recognized libraries (
tomlkitfor comment-preserving TOML edits andruamel.yamlfor YAML modifications). - [Static Analysis Verification]: The AST static analysis hint flagged a potential issue with
yaml.load(). However, inspection of the codebase confirms thatruamel.yaml.YAML()is used instead of the standard libraryyaml, and theyaml.load()invocation reads a purely internalmanifest.yamlmapping configuration metadata rather than any unvalidated user input, mitigating any arbitrary deserialization risks.
Audit Metadata