READ-ONLY PACKAGE PREVIEW

modern-python/SOURCE.md

Version 82fe82262526.bb1 · CC-BY-SA-4.0. This preview displays packaged text and does not execute code. Treat the contents as untrusted instructions.

← Return to resource and package checksum

Source, attribution and use boundaries

Modern Python by William Tan, Trail of Bits Skills and repository contributors. Pinned source: https://github.com/trailofbits/skills/tree/82fe8226252622fa807643bdca1710901198553a/plugins/modern-python/skills/modern-python License: CC BY-SA 4.0, https://creativecommons.org/licenses/by-sa/4.0/ . The complete legal text and separate publisher grant are bundled. Keep credit, source/license links and supplied notices; indicate changes and apply ShareAlike to adaptations. These are instruction materials, not an MIT or Apache software release. Names and included brand assets do not imply endorsement.

All 14 files in the original skill directory and four source-context/license files are preserved byte for byte. Relative skill/reference/template links remain complete. BB Skills adds only this SOURCE.md and BB-SKILLS-REVIEW.json; these packaging additions are also offered under CC BY-SA 4.0. The package version suffix describes independent packaging, not an upstream content change.

This bundle contains guidance for uv, Ruff, ty, pytest and optional security/dependency tools. It does not install any of them, change Python, activate a virtual environment, migrate a project or deploy a workflow. Use versions suitable for the actual project; tool preferences in the source are not proof of universal replacements or compatibility. In particular, verify the pytest version before adopting a tool.pytest TOML configuration. Existing tests, packaging metadata, lockfiles, coverage and supported Python versions must be checked before deleting or replacing legacy files. A migration's cleanup list is not authorization to remove files from an unrelated project.

The original skill's Python 3.11+ project preference is distinct from each tool's actual supported runtime. Type checking and linting do not establish runtime correctness, and an 80 percent coverage threshold does not prove useful test quality. A dependency scanner reports the advisories it knows about; it cannot certify a dependency tree free from every vulnerability.

The larger upstream Claude plugin describes SessionStart PATH shims for legacy commands. Those hook scripts and hook configuration are not in this instruction bundle and no shim is installed. Renamed plugin metadata and plugin README are source context. The included agents/openai.yaml is upstream display metadata, not a runtime evaluation. Source context relative links require the pinned repository.

The repository lists Claude Code and Codex installation paths; these are browsing labels, not tested client compatibility. This record checks source integrity, complete dependencies and license presentation only. No AI client, Python tooling command, hook, security scanner, cookiecutter generation, PyPI publication or complete migration was executed for this resource. No paid model or cloud service was used. Tools and model services have their own licenses, prerequisites and possible charges.

Review templates before copying them into GitHub Actions, Dependabot or pre-commit configuration. Downloading instructions does not authorize CI activation, package publishing, outbound network calls or paid services. Use a separate fixture with synthetic data for a practical check.