Official agent skill

Python kwargs setattr Allowlist

by microsoft in microsoft/onnxruntime

Shows how to replace unsafe hasattr and setattr loops over user-controlled kwargs with an explicit allowlist when configuring ONNX Runtime option objects.

OfficialMITAuto-check passedSecurity

Install Python kwargs setattr Allowlist

skills CLI
$ npx skills add microsoft/onnxruntime --skill python-kwargs-setattr-security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install microsoft/onnxruntime python-kwargs-setattr-security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/microsoft/onnxruntime.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.github/skills/python-kwargs-setattr-security .claude/skills/python-kwargs-setattr-security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
python-kwargs-setattr-security
GitHub stars
22k
Token cost
~737 tokens
SKILL.md length
201 words
Files
1
Skills in repo
14
Repo updated
First seen
Licence
MIT

At a glance

Shows how to replace unsafe hasattr and setattr loops over user-controlled kwargs with an explicit allowlist when configuring ONNX Runtime option objects.

  • Works in 5 steps: Use the existing object in… → RuntimeError is the ORT convention for… → Silent ignore for one path is OK when… → …
  • Reviewing Python code that forwards kwargs to setattr on option objects
  • SKILL.md covers Problem Pattern, Fix: Explicit Allowlist, Key Rules and Dangerous SessionOptions…, plus 1 more section
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

The skill explains why forwarding user-controlled kwargs through `hasattr(obj, k)` and `setattr(obj, k, v)` onto C++ extension objects such as SessionOptions and RunOptions is unsafe: `hasattr` is true for every exposed property, including dangerous ones. The fix is a module-level frozenset of safe attribute names. Known-but-blocked attributes raise a RuntimeError, while unknown keys are silently ignored.

Its rules: check against the existing options object instead of constructing a throwaway one per iteration, use RuntimeError for API misuse, allow the silent ignore only when kwargs are forwarded to a second path that validates them, name the constant `_ALLOWED_` plus the class name in capitals, and leave module-level constants without type annotations. Properties that must never be allowlisted include `optimized_model_filepath`, the profiling file prefix together with `enable_profiling`, and `register_custom_ops_library`, since they can overwrite files or load arbitrary shared libraries. The files in ONNX Runtime's Python backend and the matching allowlist test are named.

When your agent uses it

  • Reviewing Python code that forwards kwargs to setattr on option objects
  • Fixing an arbitrary-file-write risk in ONNX Runtime backend options
  • Adding a new allowlisted option together with its test

Example prompts

  • “Review this backend run function: it copies kwargs onto SessionOptions with setattr. Is that safe?”
  • “Replace the hasattr and setattr loop in backend_rep.py with an explicit allowlist.”
  • “Add a test showing that a blocked RunOptions kwarg raises RuntimeError.”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Use the existing object in hasattr(options, k) — never hasattr(ClassName(), k) (creates throwaway C++ objects per iteration)
  2. RuntimeError is the ORT convention for API misuse errors (not ValueError)
  3. Silent ignore for one path is OK when kwargs are forwarded to both paths: run_model() passes the same kwargs dict to both prepare()…
  4. Frozenset constant naming: _ALLOWED_ — ALL_CAPS, Google Style
  5. No type annotations on module-level constants (ORT Python convention)

What it can do on your machine

Read from SKILL.md and the folder at commit 8420709. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are python).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Python kwargs setattr Allowlist loads about 737 tokens when it runs. Until then it costs about 82 tokens; SKILL.md has 201 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~82
When it runs · the whole SKILL.md, loaded when a task matches
~737

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from microsoft/onnxruntime at commit 8420709, republished under its MIT licence (© microsoft). 201 words, ~737 tokens.

Download SKILL.mdSave it as .claude/skills/python-kwargs-setattr-security/SKILL.md (or your agent's skills folder).
name
python-kwargs-setattr-security
description
When reviewing or fixing Python code that uses setattr() with user-controlled kwargs to configure C++ extension objects (SessionOptions, RunOptions, etc.) in ONNX Runtime. Use this to apply the allowlist pattern that prevents arbitrary file writes and other attacks via reflected property access.

Problem Pattern

Using hasattr(obj, k) / setattr(obj, k, v) with user-controlled kwargs is insecure. The hasattr check is NOT a security guard — it returns True for ALL exposed properties including dangerous ones.

python
# INSECURE — do not use
for k, v in kwargs.items():
    if hasattr(options, k):
        setattr(options, k, v)

Fix: Explicit Allowlist

Define a module-level frozenset of safe attribute names. Raise RuntimeError for known-but-blocked attrs; silently ignore unknown keys.

python
# Define at module level, before the class
_ALLOWED_SESSION_OPTIONS = frozenset({
    "enable_cpu_mem_arena",
    "enable_mem_pattern",
    # ... only explicitly reviewed safe attrs
})

# In the method
for k, v in kwargs.items():
    if k in _ALLOWED_SESSION_OPTIONS:
        setattr(options, k, v)
    elif hasattr(options, k):  # reuse the existing instance, don't create new
        raise RuntimeError(
            f"SessionOptions attribute '{k}' is not permitted via the backend API. "
            f"Allowed attributes: {', '.join(sorted(_ALLOWED_SESSION_OPTIONS))}"
        )
    # else: silently ignore (may be kwargs for a different config object)

Key Rules

  1. Use the existing object in hasattr(options, k) — never hasattr(ClassName(), k) (creates throwaway C++ objects per iteration)
  2. RuntimeError is the ORT convention for API misuse errors (not ValueError)
  3. Silent ignore for one path is OK when kwargs are forwarded to both paths: run_model() passes the same kwargs dict to both prepare() (validates SessionOptions) and rep.run() (validates RunOptions). A RunOptions kwarg unknown to SessionOptions is silently ignored by prepare() — this is correct because rep.run() will validate it. Only raise RuntimeError when the attr exists on the target object but is blocked.
  4. Frozenset constant naming: _ALLOWED_<CLASSNAME> — ALL_CAPS, Google Style
  5. No type annotations on module-level constants (ORT Python convention)

Dangerous SessionOptions Properties (never allowlist)

  • optimized_model_filepath — triggers Model::Save(), overwrites arbitrary files
  • profile_file_prefix + enable_profiling — writes profiling JSON to arbitrary path
  • register_custom_ops_library — loads arbitrary shared libraries (method, not property)

Files in ONNX Runtime

  • onnxruntime/python/backend/backend.py — _ALLOWED_SESSION_OPTIONS
  • onnxruntime/python/backend/backend_rep.py — _ALLOWED_RUN_OPTIONS
  • Tests: onnxruntime/test/python/onnxruntime_test_python_backend.py — TestBackendKwargsAllowlist

© microsoft, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .github/skills/python-kwargs-setattr-security of microsoft/onnxruntime.

Open the folder on GitHubat commit 8420709

Compare with similar skills

Python kwargs setattr Allowlist next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Python kwargs setattr Allowlist compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Python kwargs setattr Allowlist this skillmicrosoft/onnxruntime22k—~737Automated safety check: PassMIT
CodeQL Security Scantrailofbits/skills7.4k—~4.6kAutomated safety check: NotesCC-BY-SA-4.0
Security AuditTheDecipherist/claude-code-mastery550—~1.3kAutomated safety check: NotesMIT
Agent-Core Security ChecklistopenJiuwen-ai/agent-core441—~1.7kAutomated safety check: NotesApache-2.0
API Security Hardeningsecondsky/claude-skills227—~718Automated safety check: PassMIT
Security Headers Configurationsecondsky/claude-skills227—~638Automated safety check: PassMIT

Similar skills

  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.4k GitHub stars~4.6k tokensUpdated 5 days ago
    SecurityAuto-check: notes
  • Security Audit

    TheDecipherist/claude-code-mastery

    Checks a codebase for hardcoded secrets, vulnerable dependencies, weak input handling, weak authentication and unsafe transport settings before deployment or merge.

    550 GitHub stars~1.3k tokensUpdated 5 mo ago
    SecurityAuto-check: notes
  • Agent-Core Security Checklist

    openJiuwen-ai/agent-core

    A ten-category security checklist for the agent-core codebase, to run before any security-sensitive change or pull request: secrets, input validation, SQL, access control and prompt injection.

    441 GitHub stars~1.7k tokensUpdated 7 days ago
    SecurityAuto-check: notes
  • API Security Hardening

    secondsky/claude-skills

    REST API security hardening with authentication, rate limiting, input validation, security headers.

    227 GitHub stars~718 tokensUpdated 9 days ago
    SecurityAuto-check passed
  • Security Headers Configuration

    secondsky/claude-skills

    Configures HTTP security headers to protect against XSS, clickjacking, and MIME sniffing attacks.

    227 GitHub stars~638 tokensUpdated 9 days ago
    SecurityAuto-check passed
  • Security Auditor

    eigent-ai/eigent

    Audits source code, dependencies and config files for vulnerabilities and hardcoded secrets, using two bundled Python scanners and an OWASP Top 10 checklist.

    15k GitHub stars~1.8k tokensUpdated today
    SecurityAuto-check: notes

More from microsoft/onnxruntime

All 14 skills in this repo
  • Official

    Finds and fixes out-of-range output writes in ONNX Runtime operator shape-inference functions where a getNumOutputs guard admits too few outputs.

    22k GitHub stars~3.3k tokensUpdated today
    Auto-check passed
  • Official

    Explains why editing CUTLASS fused-MHA headers in ONNX Runtime can leave stale CUDA kernels after an incremental build, and how to force and verify a real rebuild.

    22k GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • ONNX Runtime Source Build

    microsoft/onnxruntime

    Official

    Builds ONNX Runtime from source with its build scripts, explaining the update, build and test phases, key flags and where the build output lands.

    22k GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • ONNX Runtime CI Management

    microsoft/onnxruntime

    Official

    Triggers, re-runs and unblocks the CI checks on an ONNX Runtime pull request, after diagnosing whether a failure is transient or needs a code change.

    22k GitHub stars~4.1k tokensUpdated today
    Auto-check passed
  • ONNX Runtime Release Notes

    microsoft/onnxruntime

    Official

    Drafts ONNX Runtime release notes from commit history and contributor metadata using named presets for the full runtime or a scoped component.

    22k GitHub stars~1.6k tokensUpdated today
    Auto-check passed
  • ONNX Runtime Test Runner

    microsoft/onnxruntime

    Official

    Runs and debugs ONNX Runtime tests: Google Test executables for C++ and unittest or pytest for Python, with filters and build-directory guidance.

    22k GitHub stars~1.8k tokensUpdated today
    Auto-check passed

Works with

Questions about Python kwargs setattr Allowlist

What does Python kwargs setattr Allowlist do?

Shows how to replace unsafe hasattr and setattr loops over user-controlled kwargs with an explicit allowlist when configuring ONNX Runtime option objects. The skill explains why forwarding user-controlled kwargs through `hasattr(obj, k)` and `setattr(obj, k, v)` onto C++ extension objects such as SessionOptions and RunOptions is unsafe: `hasattr` is true for every exposed property, including dangerous ones. The fix is a module-level frozenset of safe attribute names.

When should I use Python kwargs setattr Allowlist?

Python kwargs setattr Allowlist fits situations like: reviewing Python code that forwards kwargs to setattr on option objects; fixing an arbitrary-file-write risk in ONNX Runtime backend options; adding a new allowlisted option together with its test.

How do I install Python kwargs setattr Allowlist in Claude Code?

Run `npx skills add microsoft/onnxruntime --skill python-kwargs-setattr-security -a claude-code`. Or copy the skill folder (.github/skills/python-kwargs-setattr-security in microsoft/onnxruntime) into .claude/skills/python-kwargs-setattr-security in your project. Claude Code loads it when a task matches its description.

How do I install Python kwargs setattr Allowlist in Codex?

Run `npx skills add microsoft/onnxruntime --skill python-kwargs-setattr-security -a codex`. Or copy the skill folder (.github/skills/python-kwargs-setattr-security in microsoft/onnxruntime) into .agents/skills/python-kwargs-setattr-security in your project. Codex loads it when a task matches its description.

Can I use Python kwargs setattr Allowlist in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add microsoft/onnxruntime --skill python-kwargs-setattr-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/python-kwargs-setattr-security, .gemini/skills/python-kwargs-setattr-security, .github/skills/python-kwargs-setattr-security and .opencode/skills/python-kwargs-setattr-security in your project.

What does Python kwargs setattr Allowlist need to run?

SKILL.md names no scripts, command-line tools or credentials: Python kwargs setattr Allowlist is instructions for the agent only.

Does Python kwargs setattr Allowlist access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Python kwargs setattr Allowlist safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Python kwargs setattr Allowlist use?

Python kwargs setattr Allowlist is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Python kwargs setattr Allowlist use?

About 737 tokens (SKILL.md is roughly 2.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Python kwargs setattr Allowlist?

Skills that share tags, products or a category with Python kwargs setattr Allowlist: CodeQL Security Scan (trailofbits/skills, 7.4k stars), Security Audit (TheDecipherist/claude-code-mastery, 550 stars), Agent-Core Security Checklist (openJiuwen-ai/agent-core, 441 stars) and API Security Hardening (secondsky/claude-skills, 227 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Python kwargs setattr Allowlist?

microsoft (a GitHub organization, an official publisher) maintains it in microsoft/onnxruntime, which has 22,029 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on October 7, 2026.

Source: microsoft/onnxruntime on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.