python-packaging
Pass
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides instructions to install standard Python packaging and development tools (e.g., build, twine, pytest, ruff, black) from official package registries. It also references official GitHub Actions from the Python Packaging Authority (pypa/cibuildwheel) and GitHub (actions/checkout).
- [COMMAND_EXECUTION]: The implementation playbook contains shell command examples for common development tasks, such as creating virtual environments, building package distributions, and performing local installation testing. These commands are standard for the skill's intended purpose.
- [CREDENTIALS_UNSAFE]: The documentation includes a template for the
.pypircconfiguration file used for authentication with PyPI. It adheres to security best practices by recommending API tokens and using descriptive placeholders for secrets rather than hardcoding credentials. - [SAFE]: All external links point to official documentation sites (packaging.python.org, pypi.org, readthedocs.io). The skill instructions focus on standard development workflows without attempting to bypass safety guidelines or perform unauthorized data access.
Audit Metadata