align-recipe-pyproject

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFE
Full Analysis
  • [Code/Dependency Analysis]: The skill uses Python scripts to read and manipulate configuration formats via standard, recognized libraries (tomlkit for comment-preserving TOML edits and ruamel.yaml for YAML modifications).
  • [Static Analysis Verification]: The AST static analysis hint flagged a potential issue with yaml.load(). However, inspection of the codebase confirms that ruamel.yaml.YAML() is used instead of the standard library yaml, and the yaml.load() invocation reads a purely internal manifest.yaml mapping configuration metadata rather than any unvalidated user input, mitigating any arbitrary deserialization risks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 05:52 AM
Security Audit — agent-trust-hub — align-recipe-pyproject