Skip to content
Back to skills

Python Security

ASecurity

Secure Python services against secret leakage, injection, unsafe subprocess calls, and dependency drift. Use when handling env vars, tokens, SQL, file paths, shell commands, auth flows, or Python security gates.

  • 549 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added September 5, 2026
developmentpythonrustshellsqlsecurity

Security analysis

A100/100

Pro scans all 2 files and shows the line behind each finding

Scanned September 5, 2026

npx -y skills add HoangNguyen0403/agent-skills-standard --skill python-security --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Python Security?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Python Security
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/hoangnguyen0403-python-security-398f3eca/badge)](https://www.skillsdirectory.com/skills/hoangnguyen0403-python-security-398f3eca)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: python-security
description: Secure Python services against secret leakage, injection, unsafe subprocess calls, and dependency drift. Use when handling env vars, tokens, SQL, file paths, shell commands, auth flows, or Python security gates.
metadata:
  triggers:
    files:
      - "requirements.txt"
      - ".env.example"
      - "**/*.py"
    keywords:
      - secret
      - token
      - subprocess
      - injection
      - sanitize
      - pip-audit
---

# Python Security

## **Priority: P0 (CRITICAL)**

## Rules

- Keep secrets in env or secret stores; never hardcode them in code or fixtures.
- Parameterize SQL and validate file or path inputs before use.
- Prefer `subprocess.run([...], shell=False)` with explicit args.
- Audit dependency surfaces and keep security gates current.

## Recipe

1. **Classify inputs**: trusted config, semi-trusted runtime data, untrusted user or PR text.
2. **Validate or normalize before boundary calls**.
3. **Redact secrets from logs, reports, and artifacts**.
4. **Use least-privilege filesystem and process execution**.
5. **Run dependency/security verification** after auth or gate changes.

## Anti-Patterns

- **No shell string execution** for user-shaped input.
- **No secrets in example configs, tests, or docs**.
- **No direct path joins from untrusted input** without root checks.
- **No "internal-only" exception to SQL or subprocess hygiene**.

## References

- [Framework Map](../references/framework-map.md)

Files in this skill

  • SKILL.md1.4 KB
  • evals/evals.json1.2 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…