python-development-python-scaffold

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill's stated goal of generating production-ready Python scaffolds is generally coherent with its content. However, there are notable security concerns primarily around the use of a non-standard 'uv' tool for initialization and package management, plus potential exposure of credentials through .env.example and ambiguous trust in dependency sources. The combination of unverifiable tooling and potential credential visibility warrants a suspicious to high-vulnerability assessment, with securityRisk leaning toward the higher end due to supply-chain and credential-handling uncertainties.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 06:52 AM
Package URL
pkg:socket/skills-sh/SivaG-lab%2Froth_mcp%2Fpython-development-python-scaffold%2F@04902e606a0ab5f6c9a28dfd99add901b1e8ee4f