best-practices-python
Pass
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as a documentation and linting suite for Python development. It explicitly promotes secure coding practices by including rules against command injection (security-no-shell-true.md), code injection (security-no-eval-exec.md), and credential leakage (security-redact-secrets.md).
- [COMMAND_EXECUTION]: The skill includes shell and Python scripts for project maintenance and verification. Scripts like 'sanity.sh' and 'sanity/lint_dotenv.sh' use standard tools (find, grep, python3) to ensure project compliance. 'scripts/check_file_limits.py' and 'analyze_packages.py' scan the local file system for Python files and dependency configurations. These operations are restricted to the local workspace and align with the skill's stated purpose.
- [DATA_EXFILTRATION]: No network communication or data transmission patterns were detected. Scripts only perform local file I/O for report generation and linting purposes.
- [PROMPT_INJECTION]: Analysis of the markdown content and metadata found no instructions attempting to override agent behavior, bypass safety protocols, or extract system prompts.
Audit Metadata