sota-python

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a technical guideline for Python development and security auditing. It employs a fictional 2026 'State of the Art' baseline for stylistic framing, providing valid and advanced technical advice.
  • [REMOTE_CODE_EXECUTION]: While the skill mentions tools that can execute code (like uv, pytest, bandit), it does so in the context of standard development workflows and security testing. It explicitly warns against dangerous patterns like eval(), exec(), and pickle.loads() on untrusted data.
  • [COMMAND_EXECUTION]: The skill provides bash command snippets for auditing projects (e.g., uvx ruff check). These are standard diagnostic commands and do not involve silent or malicious execution.
  • [EXTERNAL_DOWNLOADS]: The skill references trusted external repositories for pre-commit hooks (e.g., astral-sh/ruff-pre-commit) and standard Python toolchains. These conform to best practices for modern Python development.
  • [INDIRECT_PROMPT_INJECTION]: The skill handles code analysis, which is a potential surface for indirect injection; however, it includes instructions for 'trust-boundary thinking' and validation, encouraging safe handling of external data.
  • [DATA_EXFILTRATION]: No exfiltration patterns were found. The skill emphasizes using secrets and compare_digest for secure handling of credentials and sensitive data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 10:37 AM
Security Audit — agent-trust-hub — sota-python