modern-python
What this skill does
Configures Python projects with modern tooling (uv, ruff, ty). Use when creating projects, writing standalone scripts, or migrating from pip/Poetry/mypy/black.
github/trailofbits - Remote code execution - 6.5k stars
Threat analysis
Skill info
pkg:github/trailofbits/skills@e6066e7?skill=modern-pythonAssessments (2)
Remote code execution
Remote code execution via local-llm-review
references/security-setup.md
curl --proto '=https' --tlsv1.2 -LsSf https://github.com/j178/prek/releases/latest/download/prek-installer.sh | shRemote code execution via local-llm-review
references/uv-commands.md
curl -LsSf https://astral.sh/uv/install.sh | shBadge
Add the Anomity scan badge for modern-python to your README.
How Anomity governs this at runtime
Scan-time vetting tells you what a skill says it will do. Anomity's Endpoint Sensor sees what agents actually do: it discovers skills alongside every other AI artifact on the endpoint, and runtime governance can allow, deny, or log the tool calls a skill triggers. Policy violations route to your SIEM, Slack, email, or Jira, backed by a queryable 90-day audit trail.
Book a 30-minute demo to see your own skill inventory.
Methodology and disputes
Every skill is assessed by the Anomity Skill Intelligence engine against its public source; findings indicate risk patterns, not confirmed exploitation. Maintainer of modern-python? Report an issue or request a rescan.




