scaffold-python-project
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill downloads a standard
.gitignorefile from GitHub's official repository (github.com/github/gitignore). This is a fetch of a non-executable configuration file from a well-known and trusted source. - Evidence:
curl -fsSL https://raw.githubusercontent.com/github/gitignore/main/Python.gitignore -o .gitignoreinSKILL.md. - [COMMAND_EXECUTION]: The skill uses
uvto initialize projects and install dependencies, andprek(a pre-commit runner) to install hooks. These are standard development tasks for project scaffolding. - Evidence:
uv init,uv sync, anduv run prek installinSKILL.md. - [INDIRECT_PROMPT_INJECTION]: The skill ingests user-provided project metadata, such as the project name and author details, and interpolates them into templates for configuration files and source code. This is a standard surface for indirect prompt injection common to all scaffolding tools.
- Ingestion points: User responses to discovery questions (e.g., project name, author name) in
SKILL.md. - Boundary markers: Absent; placeholders like
<pypi-name>and<author_name>are directly substituted. - Capability inventory: The skill can write files, perform network fetches via
curl, and execute local development tools viauv. - Sanitization: Absent; the skill relies on direct substitution of user-provided strings.
Audit Metadata