Agent skill

Python Review

by liuyanghejerry in liuyanghejerry/Clausura

Python 遗留代码审查:bare except、SQL 注入、反序列化、密钥、调试输出. An agent skill from liuyanghejerry/Clausura.

MITAuto-check passedSecurity

Install Python Review

skills CLI
$ npx skills add liuyanghejerry/Clausura --skill python-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install liuyanghejerry/Clausura python-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/liuyanghejerry/Clausura.git skills-src && mkdir -p .claude/skills && cp -r skills-src/eval/scenarios/legacy-refactor/workspace/.clausura/skills/python-review .claude/skills/python-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
python-review
GitHub stars
204
Token cost
~164 tokens
SKILL.md length
46 words
Files
1
Skills in repo
5
Repo updated
First seen
Licence
MIT

At a glance

Python 遗留代码审查:bare except、SQL 注入、反序列化、密钥、调试输出. An agent skill from liuyanghejerry/Clausura.

  • Tasks that involve SQL
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Python Review is an agent skill from liuyanghejerry/Clausura. Python 遗留代码审查:bare except、SQL 注入、反序列化、密钥、调试输出

Its SKILL.md is about 160 tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering SQL. It works with Python and SQL. The repository describes itself as: CI-native agent CLI tool for deterministic pipeline gating. The licence is MIT.

When your agent uses it

  • Tasks that involve SQL

Example prompts

  • “/python-review”

Requirements

  • Python 3

What it can do on your machine

Read from SKILL.md and the folder at commit 7653c87. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Python Review loads about 164 tokens when it runs. Until then it costs about 15 tokens; SKILL.md has 46 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~15
When it runs · the whole SKILL.md, loaded when a task matches
~164

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from liuyanghejerry/Clausura at commit 7653c87, republished under its MIT licence (© liuyanghejerry). 46 words, ~164 tokens.

Download SKILL.mdSave it as .claude/skills/python-review/SKILL.md (or your agent's skills folder).
name
python-review
description
Python 遗留代码审查:bare except、SQL 注入、反序列化、密钥、调试输出

Python 遗留代码审查

先用 git_diff(参数 {"base": "HEAD~1"})查看本次变更。

规则

bare-except(error)
  • 裸 except Exception: / except: 后静默吞掉错误(仅 pass 或无处理)
  • 有日志或显式处理的除外
  • rule_id: bare-except
sql-injection(error)
  • f-string / 字符串拼接构造 SQL
  • rule_id: sql-injection
unsafe-deserialization(error)
  • pickle.loads() 反序列化不可信输入
  • rule_id: unsafe-deserialization
hardcoded-secret(error)
  • 源码中硬编码的 API key、密码
  • rule_id: hardcoded-secret
debug-print(info)
  • 生产代码中遗留的 print() 调试输出
  • rule_id: debug-print

每个 finding 附带 location(文件 + 行号)与证据(代码片段)。

© liuyanghejerry, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in eval/scenarios/legacy-refactor/workspace/.clausura/skills/python-review of liuyanghejerry/Clausura.

Open the folder on GitHubat commit 7653c87

Compare with similar skills

Python Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Python Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Python Review this skillliuyanghejerry/Clausura204—~164Automated safety check: PassMIT
Sast Sqliutkusen/sast-skills1.3k—~6kAutomated safety check: PassMIT
Gorm ExpertLeoYeAI/openclaw-master-skills2.2k—~3.4kAutomated safety check: PassMIT
Rds Oracleaws/agent-toolkit-for-aws2.8k—~6.2kAutomated safety check: PassApache-2.0
Chdb SQLvemetric/vemetric3941 repos~1.2kAutomated safety check: PassApache-2.0
Kolokoloai/kolo525—~1.2kAutomated safety check: PassNone

Similar skills

  • Sast Sqli

    utkusen/sast-skills

    Detect SQL injection vulnerabilities in a codebase using a three-phase approach: recon (find unsafe SQL construction sites), batched verify (trace user input to those sites in parallel subagents, 3…

    1.3k GitHub stars~6k tokensUpdated 6 mo ago
    SecurityAuto-check passed
  • Gorm Expert

    LeoYeAI/openclaw-master-skills

    GORM v2 最佳实践与性能优化。适用于:代码审查、慢查询优化、N+1、连接池、 事务管理、分库分表、Prometheus/OTel监控、Session安全、Clause/Upsert、 缓存集成、BaseModel脚手架、SQL→struct生成、多租户隔离。

    2.2k GitHub stars~3.4k tokensUpdated 2 mo ago
    DevOps & CloudAuto-check passed
  • Rds Oracle

    aws/agent-toolkit-for-aws

    Official

    Diagnoses and resolves Amazon RDS for Oracle connectivity, authentication, networking, and driver troubleshooting.

    2.8k GitHub stars~6.2k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Chdb SQL

    vemetric/vemetric

    A skill your agent uses when the user wants to run SQL — especially analytical SQL — on local files (parquet/csv/json), URLs, S3 paths, or remote databases (Postgres, MySQL, MongoDB, ClickHouse…

    394 GitHub starsUsed in 1 repo~1.2k tokens
    DatabasesAuto-check passed
  • Kolo

    koloai/kolo

    Kolo is a text-based Python debugger that captures every executed function, return value, local variable, HTTP request, and SQL query into greppable trace files.

    525 GitHub stars~1.2k tokensUpdated 5 mo ago
    DatabasesAuto-check passed
  • SQL Schema Policy Validator

    rominirani/antigravity-skills

    Validates SQL schema files for compliance with internal safety and naming policies.

    591 GitHub stars~264 tokensUpdated 3 mo ago
    DatabasesAuto-check passed

More from liuyanghejerry/Clausura

  • TS Review

    liuyanghejerry/Clausura

    TypeScript monorepo 审查:XSS、SQL 注入、密钥、any、console.log. An agent skill from liuyanghejerry/Clausura.

    204 GitHub stars~166 tokensUpdated 8 days ago
    Auto-check passed
  • Rust Review

    liuyanghejerry/Clausura

    Rust 服务审查:panic、SQL 注入、密钥、错误吞没、遗留标记

    204 GitHub stars~180 tokensUpdated 8 days ago
    Auto-check passed
  • Security Review

    liuyanghejerry/Clausura

    检查 SQL 注入、XSS、硬编码密钥

    204 GitHub stars~106 tokensUpdated 8 days ago
    Auto-check passed
  • Secret Sweep Scan

    liuyanghejerry/Clausura

    大规模扫描硬编码凭证,忽略占位符

    204 GitHub stars~125 tokensUpdated 8 days ago
    Auto-check passed

Works with

Questions about Python Review

What does Python Review do?

Python 遗留代码审查:bare except、SQL 注入、反序列化、密钥、调试输出. An agent skill from liuyanghejerry/Clausura. Python Review is an agent skill from liuyanghejerry/Clausura.

When should I use Python Review?

Python Review fits situations like: tasks that involve SQL.

How do I install Python Review in Claude Code?

Run `npx skills add liuyanghejerry/Clausura --skill python-review -a claude-code`. Or copy the skill folder (eval/scenarios/legacy-refactor/workspace/.clausura/skills/python-review in liuyanghejerry/Clausura) into .claude/skills/python-review in your project. Claude Code loads it when a task matches its description.

How do I install Python Review in Codex?

Run `npx skills add liuyanghejerry/Clausura --skill python-review -a codex`. Or copy the skill folder (eval/scenarios/legacy-refactor/workspace/.clausura/skills/python-review in liuyanghejerry/Clausura) into .agents/skills/python-review in your project. Codex loads it when a task matches its description.

Can I use Python Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add liuyanghejerry/Clausura --skill python-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/python-review, .gemini/skills/python-review, .github/skills/python-review and .opencode/skills/python-review in your project.

What does Python Review need to run?

SKILL.md names no scripts, command-line tools or credentials: Python Review is instructions for the agent only. Our summary lists: Python 3.

Does Python Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Python Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Python Review use?

Python Review is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Python Review use?

About 164 tokens (SKILL.md is roughly 656 characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Python Review?

Skills that share tags, products or a category with Python Review: Sast Sqli (utkusen/sast-skills, 1.3k stars), Gorm Expert (LeoYeAI/openclaw-master-skills, 2.2k stars), Rds Oracle (aws/agent-toolkit-for-aws, 2.8k stars) and Chdb SQL (vemetric/vemetric, 394 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Python Review?

liuyanghejerry (a GitHub user) maintains it in liuyanghejerry/Clausura, which has 204 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on September 29, 2026.

Source: liuyanghejerry/Clausura on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.