python-pro
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill represents a standard attack surface for indirect prompt injection as it involves reading and processing codebase files and executing development tools.- Ingestion points: Reads project source code, configuration files (pyproject.toml), and dependency manifests (SKILL.md, references/packaging.md).- Boundary markers: No specific boundary markers or 'ignore' instructions for external code content are defined.- Capability inventory: Executes command-line tools including mypy, black, ruff, and pytest, and performs file system operations (SKILL.md, references/standard-library.md).- Sanitization: Relies on the agent's internal safety filters and standard tool outputs; no explicit sanitization of codebase content is described.- [SAFE]: The skill provides high-quality, professional guidance for Python development. All tools and packages referenced are well-known industry standards (e.g., pytest, mypy, ruff, poetry). The instructions emphasize security best practices, such as avoiding hardcoded secrets and using proper resource management.
Audit Metadata