li-python-sec-checkPython 安全规范检查工具 - 基于 CloudBase 规范 + 腾讯安全指南 + LLM 智能分析(LLM 功能默认禁用,本地执行优先)
Install via ClawdBot CLI:
clawdbot install 43622283/li-python-sec-checkGrade Limited — based on market validation, documentation quality, package completeness, maintenance status, and authenticity signals.
Potentially destructive shell commands in tool definitions
eval (Calls external URL not in known-safe list
https://img.shields.io/badge/License-MIT-yellow.svgAI Analysis
The skill's primary risk is the presence of an `eval()` function, which could be unsafe if user-controlled code is passed to it, but this is a known static analysis finding for a security tool itself. The external badge URL is benign and does not indicate data exfiltration. No evidence of credential harvesting, hidden instructions, or obfuscation was found in the provided snippet.
Audited Apr 17, 2026 · audit v1.0
Generated May 6, 2026
Integrate into CI/CD pipelines to automatically scan Python code for security vulnerabilities and compliance with CloudBase and Tencent security standards, blocking insecure code from merging. Ideal for DevSecOps teams in high-regulatory environments.
Run periodic audits of existing Python repositories to ensure adherence to internal security policies and generate reports for compliance officers. Useful for organizations subject to SOC2 or PCI-DSS.
Provide immediate feedback to developers during coding, highlighting potential security flaws and suggesting fixes before commit. Enhances developer security awareness without blocking workflow.
Assess third-party Python libraries or vendor source code for security risks before integration into internal systems, especially in supply chain security programs.
When enabled, leverage LLM to interpret complex security findings and generate natural language explanations, making reports accessible to non-expert stakeholders.
Offer the tool as a cloud-based service with tiered pricing based on number of developers or repositories scanned. Includes support and updates for security rules.
Sell perpetual licenses for on-premise deployment, targeting enterprises with strict data sovereignty requirements. Additional annual maintenance contracts for updates and support.
Provide a free basic version (e.g., CLI tool with limited rules) to attract individual developers, then monetize advanced features like LLM integration, custom rule engines, and compliance dashboards for enterprise teams.
💬 Integration Tip
For quick adoption, add 'li-python-sec-check' to your pre-commit hooks or CI pipeline as a script step; the default LLM feature is off, so no API keys needed for basic static analysis.
Scored May 6, 2026
Humanize AI-generated text to bypass detection. This humanizer rewrites ChatGPT, Claude, and GPT content to sound natural and pass AI detectors like GPTZero,...
AI brainstorming and strategy thinking partner powered by CellCog. Reasoning, problem-solving, ideation, strategic planning — then execution across every modality: research, documents, visuals, data, prototypes. Think, build, review, repeat.
Generate ideas fast. Adapt depth and structure to what the user actually needs.
Evaluate any AI skill's quality through step-by-step diagnosis — measuring trigger accuracy, per-step execution (completion/correctness/quality), efficiency,...
通过调用 Prana 平台上的远程 agent 完成以下处理:基于100个热门TradingView Pine Script指标转换的Python技术分析工具集,提供专业的技术指标计算、分析和可视化功能 IMPORTANT: This skill has a mandatory step-by-step proc...
Provides a structured screening for stress perception using the PSS-10 scale as an independent skill in ClawHub.