Informe de auditoría del skill
python-env-manager Informe de auditoría.
Single source of truth for "which Python environment manager does this project use, and how do I install a package with it?". Owns the detection table (pixi / uv / poetry / hatch / conda+mamba / pip+venv), the install / remove / upgrade commands per manager, and the bootstrap path when no manager is in place (default recommendation: pixi). Stops at "the install command was issued with the right manager and the package is importable". TRIGGER when (any of these): (1) **about to install / add / pin / upgrade / remove a Python package** — `pip install`, `pixi add`, `uv add`, `poetry add`, `conda install`, etc. — under any framing; (2) `data-science-python-stack` § "Missing dependency" surfaced a missing import and an install is the next step; (3) a workflow skill's Stop condition fired on a missing dependency (`build-ml-pipeline`, `evaluate-ml-pipeline`, `organize-ml-workspace`, `audit-ml-pipeline`); (4) starting a new Python project and no manager is in place yet (bootstrap with pixi unl
Trust Score de OpenAgentSkill
Trust Score de OpenAgentSkill
The Trust Score helps an agent decide whether a skill is safe enough to shortlist before installation.
Adopción en GitHub
Info62
119 estrellas de GitHub
Actividad de stars/forks
Advertencia51
119 estrellas y 7 forks; la actividad de issues no está disponible en los metadatos actuales
Mantenimiento reciente
Aprobado88
2 meses desde el último push
Claridad de licencia
Aprobado86
BSD-3-Clause
Completitud de README/SKILL.md
Aprobado86
Los metadatos incluyen suficiente contexto de uso y flujo de trabajo
Riesgo de dependencias/runtime
Advertencia44
command execution surface, credential or environment access
Disponibilidad de instalación
Aprobado92
npx skills add probabl-ai/skills --skill python-env-manager
Seguridad del comando de instalación
Aprobado92
Ruta estándar de paquete o instalación en tiempo de ejecución
Superficie de permisos
Fallido36
secrets or environment access, shell or command execution
Evidencia del repositorio
Aprobado86
https://github.com/probabl-ai/skills/tree/main/skills/python-env-manager
Estado de revisión
Info66
Hay datos de revisión por IA disponibles
Resultados comprobados por Agent
Info54
Aún no hay datos de resultados del Agent
Comprobaciones
Revisión de instalación y adopción
Ruta de instalación
92
npx skills add probabl-ai/skills --skill python-env-manager
Repositorio
88
https://github.com/probabl-ai/skills/tree/main/skills/python-env-manager
Licencia
86
BSD-3-Clause
Mantenimiento
88
2 meses desde el último push
Revisión por IA
55
The skill references gates (G-ENV-MGR, G-ENV-SCOPE, etc.) that are defined in other skills; ensure those are available when this skill is used in isolation.
Completitud de README/SKILL.md
86
Usable description available
Riesgo de dependencias
44
command execution surface, credential or environment access
Seguridad del comando de instalación
92
Ruta estándar de paquete o instalación en tiempo de ejecución
Superficie de permisos
36
secrets or environment access, shell or command execution
Actividad de stars/forks
51
119 estrellas y 7 forks; la actividad de issues no está disponible en los metadatos actuales
Adopción
68
119 estrellas de GitHub
Financial decision safety
58
Research-only use: do not treat output as financial advice or execute a position without human approval.
Advertencias
- Dependency or permission surface needs review
- Permission surface may require sandboxing
- Financial research output is not financial advice; require human review before any live investment decision
- The skill references gates (G-ENV-MGR, G-ENV-SCOPE, etc.) that are defined in other skills; ensure those are available when this skill is used in isolation.
- The SKILL.md is very long and dense; it may be challenging for an agent to parse all rules quickly, though the structure is logical.
- Financial research output is not financial advice; require human review before any live investment decision.
- Quality score needs review
- Permission surface needs review: secrets or environment access, shell or command execution
- Stars/forks activity: 119 stars, 7 forks; issue activity unavailable in current metadata
- Dependency/runtime risk: command execution surface, credential or environment access
- Permission surface: secrets or environment access, shell or command execution
Método
This report combines public metadata, AI review output, repository freshness, install readiness, OpenAgentSkill events, quality scoring, trust checks, and the agent safety gate. It is not a full source-code security review.
Comparar opciones cercanas
Skills relacionados para auditar después
Wazuh
Wazuh - The Open Source Security Platform. Unified XDR and SIEM protection for endpoints and cloud workloads.
16K Estrellas · Informe de auditoría
Maigret
🕵️♂️ Collect a dossier on a person by username from 3000+ sites
33K Estrellas · Informe de auditoría
Nuclei
Nuclei is a fast, customizable vulnerability scanner powered by the global security community and built on a simple YAML-based DSL, enabling collaboration to tackle trending vulnerabilities on the internet. It helps you find vulnerabilities in your applications, APIs, networks, DNS, and cloud configurations.
29K Estrellas · Informe de auditoría