scaffold-python-project

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill fetches a standard Python .gitignore file from the official github/gitignore repository on GitHub using curl. This is a routine initialization task that targets a well-known service and does not execute remote code.
  • [PROMPT_INJECTION]: The skill includes engineering guideline templates that instruct agents in generated projects to "override any agent default that biases toward minimal or expedient changes." This is a quality-of-service directive for software design in the output project and does not target the safety filters or behavioral constraints of the agent executing the skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 09:23 PM
Security Audit — agent-trust-hub — scaffold-python-project