skills/k5-mot/skills/python-dev/Gen Agent Trust Hub

python-dev

Pass

Audited by Gen Agent Trust Hub on Aug 12, 2026

Risk Level: SAFE
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The setup instructions in references/setup.md include downloading and executing the official installation script for the uv tool from https://astral.sh/uv/install.sh. This is an expected and documented procedure for this well-known development utility.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes project-specific data which could potentially contain malicious instructions.
  • Ingestion points: Project source code, pyproject.toml, and .pre-commit-config.yaml as described in SKILL.md and references/lint-rules.md.
  • Boundary markers: None identified.
  • Capability inventory: Execution of development tools (ruff, pytest, pip-audit, playwright) via the uv subprocess runner as specified in references/verification.md.
  • Sanitization: None identified, as the skill operates on local project files within a development workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 12, 2026, 04:50 PM
Security Audit — agent-trust-hub — python-dev