python-developer
Pass
Audited by Gen Agent Trust Hub on May 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides extensive, high-quality documentation on security best practices, including explicit instructions for preventing SQL injection, path traversal, and unsafe use of
eval()andexec(). - [SAFE]: The Pull Request review workflow defined in
SKILL.mduses standard GitHub CLI tools (gh pr view,gh pr diff) and includes a 'Human-in-the-loop' requirement, ensuring the agent does not post comments or approvals without explicit user review. - [SAFE]: The skill instructions proactively address data exposure by mandating the use of environment variables and
.envfiles for secrets management, and by warning against logging sensitive data. - [SAFE]: No obfuscation, data exfiltration, or malicious prompt injection patterns were found. The skill appears to be a legitimate developer tool designed to improve code quality and security.
Audit Metadata