Agent skill

Openssf Python Review

by SpecterOps in SpecterOps/skills

Perform adversarial Python security code reviews grounded in the OpenSSF Secure Coding Guide for Python.

Apache-2.0Auto-check passedDevelopment

Install Openssf Python Review

skills CLI
$ npx skills add SpecterOps/skills --skill openssf-python-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install SpecterOps/skills openssf-python-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/SpecterOps/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/openssf-python-review .claude/skills/openssf-python-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
openssf-python-review
GitHub stars
702
Token cost
~2.3k tokens
SKILL.md length
1,042 words
Files
7 (incl. references)
Skills in repo
38
Repo updated
First seen
Licence
Apache-2.0

At a glance

Perform adversarial Python security code reviews grounded in the OpenSSF Secure Coding Guide for Python.

  • Works in 6 steps: Build a Python-aware inventory. → Model attacker positions and trust… → Triage high-risk Python surfaces first. → …
  • Codex needs to audit large Python repositories
  • SKILL.md covers Review Principles, References, Review Process and Finding Standard
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Openssf Python Review is an agent skill from SpecterOps/skills. Perform adversarial Python security code reviews grounded in the OpenSSF Secure Coding Guide for Python. Use when Codex needs to audit large Python repositories, recovered or decompiled Python source, Python services or scripts with unclear trust boundaries, or code paths involving Python-specific injection, deserialization, archive extraction, import-path, encoding, numeric, concurrency, logging, exception, resource-management, secret-handling, or randomness risks.

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including reference files (for example `agents/openai.yaml`, `references/large-python-project-triage.md` and `references/openssf-python-rule-index.md`).

It sits in Development, covering Code review and Secure coding. It works with Python. The repository describes itself as: A marketplace for LLM skills. The licence is Apache-2.0.

When your agent uses it

  • Codex needs to audit large Python repositories
  • Decompiled Python source
  • Python services
  • Scripts with unclear trust boundaries

Example prompts

  • “/openssf-python-review”

Requirements

  • Python 3

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Build a Python-aware inventory.
  2. Model attacker positions and trust boundaries.
  3. Triage high-risk Python surfaces first.
  4. Review integrity and availability paths.
  5. Validate each candidate end to end.
  6. Build PoC artifacts.

What it can do on your machine

Read from SKILL.md and the folder at commit e655f93. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Openssf Python Review loads about 2.3k tokens when it runs, and up to ~16k if it reads all its reference files. Until then it costs about 123 tokens; SKILL.md has 1,042 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~123
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~16k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from SpecterOps/skills at commit e655f93, republished under its Apache-2.0 licence (© SpecterOps). 1,042 words, ~2,276 tokens.

Download SKILL.mdSave it as .claude/skills/openssf-python-review/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
openssf-python-review
description
Perform adversarial Python security code reviews grounded in the OpenSSF Secure Coding Guide for Python. Use when Codex needs to audit large Python repositories, recovered or decompiled Python source, Python services or scripts with unclear trust boundaries, or code paths involving Python-specific injection, deserialization, archive extraction, import-path, encoding, numeric, concurrency, logging, exception, resource-management, secret-handling, or randomness risks.

OpenSSF Python Review

Use this skill for manual Python review when the result needs OpenSSF Python rule coverage plus the evidence standard of the local OWASP and CWE review skills. Prefer a narrower framework or platform skill when one clearly fits; use this skill to drive Python-specific adversarial review and to make recovered-source uncertainty explicit.

Review Principles

  • Start from architecture, trust boundaries, attacker-controlled inputs, sensitive assets, privilege levels, and Python runtime assumptions.
  • Treat OpenSSF rules as coverage prompts and root-cause clues, not as proof. Confirm a reachable path before reporting a finding.
  • Prioritize paths that cross trust zones or reach code execution, deserialization, query execution, archive extraction, filesystem, import resolution, secrets, authorization, logs, error output, randomness, and shared state.
  • Assume attackers will exploit alternate encodings, malformed archives, crafted object state, client-controlled identity fields, poisoned environment variables, thread timing, exceptional control flow, and recovered-source gaps.
  • Distinguish confirmed vulnerabilities from suspicious patterns, hardening opportunities, and unanswered questions.
  • For recovered source, separate what is visible in code from what may be missing because of decompilation, packaging, generated wrappers, native extensions, or absent deployment configuration.
  • Use the guide's linked CWE as an initial mapping candidate. Validate the primary CWE with the local cwe-code-review skill when precise mapping matters or when the guide's CWE is broader than the proven root cause.
  • Always create or update one standalone poc_<finding_slug>.py artifact per confirmed finding in the review workspace.

References

Review Process

  1. Build a Python-aware inventory.

    • Identify packages, entry points, frameworks, CLI commands, workers, schedulers, message consumers, plugins, imports, native bindings, templates, configuration loaders, secrets providers, storage, and deployment/runtime boundaries.
    • Identify Python version assumptions, dependency manifests, generated code, vendored packages, bytecode-only areas, and native or C-extension handoffs.
    • Record which components run under distinct OS identities or trust zones and which share one interpreter, filesystem, environment, cache, or database role.
  2. Model attacker positions and trust boundaries.

    • Enumerate HTTP/RPC parameters, headers, cookies, uploaded files, archives, queues, task payloads, database records, environment variables, config files, command-line arguments, import paths, plugin names, serialized blobs, and operator-controlled inputs.
    • Mark security decisions that depend on client-supplied identity, role, tenant, path, locale, encoding, type, numeric value, or exception behavior.
    • For recovered source, note missing call sites, unresolved imports, placeholder names, dead code uncertainty, and configuration that must be verified outside the recovered tree.
  3. Triage high-risk Python surfaces first.

    • Trace untrusted data to subprocess, os.system, SQL execution, pickle, marshal, YAML/object loaders, archive extractors, path resolution, dynamic import, eval/exec, logging, error rendering, secret loading, and token generation.
    • Check canonicalization before validation, allowlists over denylists, consistent encodings, server-side access decisions, and import/search-path integrity.
    • Review packaging and deployment artifacts for embedded secrets, debug tools, monkey patches, permissive environment inheritance, and shared-process trust-zone collapse.
  4. Review integrity and availability paths.

    • Inspect numeric conversions, Decimal construction, float comparisons, special float values, fixed-width or C-backed numbers, bitwise arithmetic, and loop counters when they influence money, quotas, sizes, timeouts, authorization, or resource limits.
    • Inspect exception handling, finally blocks, return-value handling, assertions, cleanup, locks, thread pools, shared mutable state, thread-local reuse, and silent worker failures.
    • Treat business-state corruption, fail-open behavior, denial of service, and audit blind spots as security issues when an attacker can influence the path.
  5. Validate each candidate end to end.

    • Trace source -> parsing -> normalization -> validation -> authorization -> transformation -> sink -> impact.
    • Identify the attacker capability, required state, bypassed or missing control, Python behavior that makes the path exploitable, and concrete impact.
    • Read the relevant reference section and rule entry before naming an OpenSSF rule or CWE.
    • Keep scanner hits, dangerous APIs, and decompiler oddities as leads until the full path is proven.
  6. Build PoC artifacts.

    • Create or update one standalone poc_<finding_slug>.py file for each confirmed finding.
    • Make each PoC incremental: print or implement numbered steps for prerequisites, material acquisition, trigger, impact verification, and cleanup guidance.
    • State attacker position, required permissions, credentials or certificates, environmental dependencies, Python/runtime assumptions, and any unproven prerequisite before sending requests or touching state.
    • Default to dry-run or harmless markers and require an explicit flag for state-changing validation.
    • If a finding has no safe runnable path, still create its per-finding PoC scaffold and explain the missing prerequisite or unsafe step.
    • Validate each script with syntax checks and dry runs, then record which live steps were and were not executed.
Show full SKILL.md (242 more words)Show less

Finding Standard

Lead with findings ordered by severity. For each finding include Severity, Location, Issue, OpenSSF Rule, CWE, Evidence, Exploit Path, Impact, Remediation, Test, and PoC Requirements.

For OpenSSF Rule, include the pyscg-XXXX identifier, rule name, and one sentence explaining why the code path violates that rule. If multiple rules contribute, name one primary rule and mention secondary rules only when they explain a distinct contributing failure.

For CWE, include the identifier, name, and one sentence explaining why that entry is the precise root-cause mapping. If the guide's CWE is only a candidate or a broad mapping, say so and validate with the local CWE corpus before presenting it as primary.

For Evidence, include line-scoped fenced code blocks with an appropriate language tag such as python, toml, yaml, json, bash, sql, or dockerfile. Put the source path and line range immediately above each block. Keep excerpts narrow enough to show the input, missing control, Python behavior, and sink without dumping whole modules.

For each finding, reference the corresponding poc_<finding_slug>.py artifact and include the minimum attacker position, required permissions or credentials, environmental conditions, safe default behavior, and example invocation.

After findings, include Open Questions / Assumptions and Coverage. In Coverage, list reviewed Python packages, entry points, trust boundaries, OpenSSF rule groups applied, recovered-source gaps, and tests or live validation not performed. If no confirmed findings exist, say so explicitly and still state unresolved risks, review gaps, and that no per-finding PoC artifacts were created.

© SpecterOps, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (references) in skills/openssf-python-review of SpecterOps/skills.

  • SKILL.md
  • agents/openai.yaml
  • references/large-python-project-triage.md
  • references/openssf-python-rule-index.md
  • references/python-state-and-availability-surfaces.md
  • references/python-trust-boundary-surfaces.md
  • references/recovered-python-source-review.md

Open the folder on GitHubat commit e655f93

Compare with similar skills

Openssf Python Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Openssf Python Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Openssf Python Review this skillSpecterOps/skills702—~2.3kAutomated safety check: PassApache-2.0
Structured Code ReviewFareedKhan-dev/claude-code-from-scratch298—~809Automated safety check: PassMIT
Code Review ChecklistshareAI-lab/learn-claude-code78k5 repos~1.1kAutomated safety check: PassMIT
Dignified Python Standardsdocling-project/docling68k—~1.5kAutomated safety check: PassApache-2.0
Code Review Skillawesome-skills/code-review-skill2.1k—~2.8kAutomated safety check: NotesMIT
Docling Pull Request Reviewdocling-project/docling68k—~1kAutomated safety check: PassMIT

Similar skills

  • Structured Code Review

    FareedKhan-dev/claude-code-from-scratch

    Gives the agent a five-step review routine that reads the full file first, labels each finding as bug, security, performance, style or suggestion, and ends with a summary.

    298 GitHub stars~809 tokensUpdated 6 mo ago
    DevelopmentAuto-check passed
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 5 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Dignified Python Standards

    docling-project/docling

    Applies opinionated production Python conventions chosen by the project's Python version: modern type syntax, pathlib, explicit checks and interface guidance.

    68k GitHub stars~1.5k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Code Review Skill

    awesome-skills/code-review-skill

    Provides comprehensive code review guidance for React 19, Vue 3, Angular 17+, Svelte 5, Rust, TypeScript, Java, Java 8, PHP, Ruby, Rails, Python, Django, FastAPI, Go, C/.NET, Kotlin, Swift, Dart…

    2.1k GitHub stars~2.8k tokensUpdated 29 days ago
    DevelopmentAuto-check: notes
  • Docling Pull Request Review

    docling-project/docling

    Reviews or re-reviews a Docling pull request in fixed stages, with findings that can be reproduced and an explicit record of every check that was run.

    68k GitHub stars~1k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Git History Bug Audit

    ben-manes/caffeine

    Audits a module by walking its git history commit by commit, tracking unresolved issues forward, and reporting the ones that survive to HEAD as findings.

    18k GitHub stars~3.3k tokensUpdated yesterday
    DevelopmentAuto-check passed

More from SpecterOps/skills

All 38 skills in this repo
  • Codex Activity Report

    SpecterOps/skills

    Generate a normalized UTC timeline and evidence-based narrative from Codex activity artifacts.

    702 GitHub stars~805 tokensUpdated 14 days ago
    Auto-check passed
  • Com Proxy Triage

    SpecterOps/skills

    A skill your agent uses when the user wants to triage Windows COM proxy/hijack candidates by capturing HKCU\Software\Classes\CLSID\{...}\InProcServer32 NAME NOT FOUND lookups for a process, mapping…

    702 GitHub stars~1.5k tokensUpdated 14 days ago
    Auto-check passed
  • Cwe Code Review

    SpecterOps/skills

    Perform CWE-grounded security code reviews and precise weakness mapping using a locally derived MITRE CWE corpus, relationship graphs, mapping notes, detection methods, mitigations, and schema…

    702 GitHub stars~2.4k tokensUpdated 14 days ago
    Auto-check passed
  • Ghostwriter Oplog

    SpecterOps/skills

    A skill your agent uses for Ghostwriter operation log entries from Codex, including config guidance, quick notes, evidence-backed entries, and guided oplog capture through the Ghostwriter MCP tools.

    702 GitHub stars~665 tokensUpdated 14 days ago
    Auto-check passed
  • Nmap Parse

    SpecterOps/skills

    Parse nmap scan output and generate actionable recon notes. An agent skill from SpecterOps/skills.

    702 GitHub stars~738 tokensUpdated 14 days ago
    Auto-check passed
  • Osint Recon

    SpecterOps/skills

    Perform OSINT and external reconnaissance for approved targets.

    702 GitHub stars~813 tokensUpdated 14 days ago
    Auto-check passed

Works with

Categories

Questions about Openssf Python Review

What does Openssf Python Review do?

Perform adversarial Python security code reviews grounded in the OpenSSF Secure Coding Guide for Python. Openssf Python Review is an agent skill from SpecterOps/skills. Perform adversarial Python security code reviews grounded in the OpenSSF Secure Coding Guide for Python.

When should I use Openssf Python Review?

Openssf Python Review fits situations like: Codex needs to audit large Python repositories; decompiled Python source; Python services; scripts with unclear trust boundaries.

How do I install Openssf Python Review in Claude Code?

Run `npx skills add SpecterOps/skills --skill openssf-python-review -a claude-code`. Or copy the skill folder (skills/openssf-python-review in SpecterOps/skills) into .claude/skills/openssf-python-review in your project. Claude Code loads it when a task matches its description.

How do I install Openssf Python Review in Codex?

Run `npx skills add SpecterOps/skills --skill openssf-python-review -a codex`. Or copy the skill folder (skills/openssf-python-review in SpecterOps/skills) into .agents/skills/openssf-python-review in your project. Codex loads it when a task matches its description.

Can I use Openssf Python Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add SpecterOps/skills --skill openssf-python-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/openssf-python-review, .gemini/skills/openssf-python-review, .github/skills/openssf-python-review and .opencode/skills/openssf-python-review in your project.

What does Openssf Python Review need to run?

SKILL.md names no scripts, command-line tools or credentials: Openssf Python Review is instructions for the agent only. Our summary lists: Python 3.

Does Openssf Python Review access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Openssf Python Review safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Openssf Python Review use?

Openssf Python Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Openssf Python Review use?

About 2.3k tokens (SKILL.md is roughly 9.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 14k tokens, read only when the agent opens those files.

What are the alternatives to Openssf Python Review?

Skills that share tags, products or a category with Openssf Python Review: Structured Code Review (FareedKhan-dev/claude-code-from-scratch, 298 stars), Code Review Checklist (shareAI-lab/learn-claude-code, 78k stars), Dignified Python Standards (docling-project/docling, 68k stars) and Code Review Skill (awesome-skills/code-review-skill, 2.1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Openssf Python Review?

SpecterOps (a GitHub organization) maintains it in SpecterOps/skills, which has 702 GitHub stars. The repository holds 38 skills in this directory. The repository was last updated on September 23, 2026.

Source: SpecterOps/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.