prepare-python-recipe

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • Command Execution: The skill orchestrates multiple build and validation steps by executing shell commands such as uv, ruff, and pytest. This is part of the skill's core functionality for automating developer workflows within a repository context.
  • Execution of Locally Generated Code: In Phase 7, the skill uses pytest to execute a test file (tests/test_runnability.py) that is either generated in Phase 6 or already present in the target directory. This step involves running code locally to verify the recipe's integrity.
  • Indirect Prompt Injection Surface: The skill processes data from the repository, which could potentially be used to influence agent behavior through instructions embedded in recipe files.
  • Ingestion points: The skill reads contents from manifest.yaml (Phase 1), Python source files (Phase 2), and pyproject.toml (Phase 3) to perform alignment and extraction.
  • Boundary markers: No explicit delimiters or instructions to ignore embedded commands are present during the file reading and interpolation steps.
  • Capability inventory: The skill possesses the ability to modify local files, perform dependency locking via uv, and execute Python code via pytest.
  • Sanitization: While the skill performs structural validation (e.g., regex checks for folder names), it does not specifically sanitize natural language content within the repository files against prompt injection patterns.
  • Tooling Integration: The skill integrates with standard Python development tools including uv for dependency management and ruff for code linting.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 05:53 AM
Security Audit — agent-trust-hub — prepare-python-recipe