python-pro

Pass

Audited by Gen Agent Trust Hub on Jul 29, 2026

Risk Level: SAFE
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill incorporates a security-positive constraint that explicitly forbids hardcoding secrets or configuration values, promoting secure development practices.
  • [EXTERNAL_DOWNLOADS]: The skill references standard, reputable Python development tools and libraries, including httpx, pytest, mypy, ruff, black, pydantic, and poetry, which are appropriate for its stated purpose.
  • [SAFE]: The documentation link targets GitHub Pages (jeffallan.github.io), a well-known and trusted service for hosting project documentation.
  • [PROMPT_INJECTION]: The skill is subject to an indirect prompt injection surface due to its codebase analysis workflow. Ingestion points: Project structure and source code files are analyzed by the agent. Boundary markers: None are defined to isolate untrusted code content from instructions. Capability inventory: The agent can generate code, write files, and execute validation tools like pytest and mypy. Sanitization: No specific escaping or content validation is implemented for analyzed source data.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 29, 2026, 10:42 AM
Security Audit — agent-trust-hub — python-pro