DEVELOPMENT WORKFLOW / Trail of Bits
Modern Python
Sets up or modernizes Python projects with uv, Ruff, pytest and explicit migration checks.
“Configures Python projects with modern tooling (uv, ruff, ty). Use when creating projects, writing standalone scripts, or migrating from pip/Poetry/mypy/black.”
01 / THE REASONING
Why this made the selection.
- Separates new-project setup from requested migration and documents when legacy Python requirements are outside its preferred path.
- Covers environment, dependency, lint, test and packaging configuration together, with supporting migration references.
02 / THE REVIEW RECORD
What we actually inspected.
Source review has boundaries.
A clear record is more useful than a “safe” badge.
Material inspected
- plugins/modern-python/skills/modern-python/SKILL.md (complete frontmatter and body)
- https://github.com/trailofbits/skills/blob/82fe8226252622fa807643bdca1710901198553a/LICENSE (applicable licence text)
- README.md (complete marketplace installation guidance)
Our findings
- Separates new-project setup from requested migration and documents when legacy Python requirements are outside its preferred path.
- Covers environment, dependency, lint, test and packaging configuration together, with supporting migration references.
- Writes configuration, installs dependencies, runs project tests and may remove replaced environment/configuration files during an approved migration.
Not established by this review
- Host discovery, task execution and model quality were not tested.
- Referenced helpers, sibling plugins and external service operations were not exhaustively audited or executed.
The review applies to the material and revision named here. A newer upstream release can change its behavior.
03 / PUT IT TO WORK
Add a skill to your workflow.
DOCUMENTED COMMAND
/plugin marketplace add trailofbits/skills Copying does not execute this command. It may retrieve a newer version than the reviewed source.
- In Claude Code, add the upstream marketplace, then use /plugin menu to select the modern-python plugin. Adding a marketplace alone does not install a plugin.
- The marketplace command follows upstream HEAD. To reproduce this review, obtain revision 82fe8226252622fa807643bdca1710901198553a and configure the complete checked-out plugin through the host’s local-plugin workflow.
- Keep the whole plugin, including its references, scripts and named agents; inspect its tool access before an authorized task.
Before you start
- Python 3.11 or newer for the preferred workflow; uv and the selected development tools.
04 / FOLLOW THE EVIDENCE
The source trail.
Our notes are separate from the original resource.
Check upstream before adopting a new version.
- Skill definition ↗Checked
https://github.com/trailofbits/skills/blob/82fe8226252622fa807643bdca1710901198553a/plugins/modern-python/skills/modern-python/SKILL.md
Supports: summary, whySelected, limitations, access, review
- Repository licence ↗Checked
https://github.com/trailofbits/skills/blob/82fe8226252622fa807643bdca1710901198553a/LICENSE
Supports: Redistribution terms
- Install instructions ↗Checked
https://github.com/trailofbits/skills/blob/82fe8226252622fa807643bdca1710901198553a/README.md
Supports: Documented install command