python-ultimate
Pass
Audited by Gen Agent Trust Hub on May 6, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill includes local Python scripts (e.g.,
assets/check_path_naming.pyand those in theexamples/directory) designed to validate project naming conventions and automate code transformations. These scripts are intended to be run locally by the developer viauv run. - [DATA_EXPOSURE]: Several example scripts access and process the local codebase to perform audits and refactoring (e.g.,
examples/bulk_refactor.pyandexamples/codebase_audit.py). This behavior is transparent and consistent with the skill's primary purpose of code maintenance. - [EXTERNAL_DOWNLOADS]: The documentation references standard and well-known Python packages (such as
requests,numpy, andtyper) and Node.js middleware for rate limiting. These are documented as architectural recommendations rather than hidden or suspicious downloads. - [PROMPT_INJECTION]: The skill provides structural guidance for code reviews and debugging (e.g.,
references/code-review.md), instructing the agent to maintain technical rigor and avoid performative agreement. These instructions are task-specific and do not attempt to bypass safety filters or extract system prompts.
Audit Metadata