Official agent skill

Modern Python Tooling

by trailofbits in trailofbits/skills

Sets up Python projects and standalone scripts with uv, ruff, ty, pytest and prek, and helps move existing projects off pip, Poetry, mypy and black.

OfficialCC-BY-SA-4.0Auto-check passedDevelopment

Install Modern Python Tooling

skills CLI
$ npx skills add trailofbits/skills --skill modern-python -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install trailofbits/skills modern-python --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/modern-python/skills/modern-python .claude/skills/modern-python && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
modern-python
GitHub stars
7.4k
Token cost
~2.5k tokens
SKILL.md length
755 words
Files
14 (incl. references, assets)
Skills in repo
79
Repo updated
First seen
Licence
CC-BY-SA-4.0

At a glance

Sets up Python projects and standalone scripts with uv, ruff, ty, pytest and prek, and helps move existing projects off pip, Poetry, mypy and black.

  • Works in 4 steps: Create Project Structure → Configure pyproject.toml → Install Dependencies → …
  • Creating a new Python package with a pyproject.toml
  • SKILL.md covers When to Use This Skill, When NOT to Use This Skill, Anti-Patterns to Avoid and Decision Tree, plus 8 more sections
  • Calls uv and uvx; reaches httpbin.org

What it does

The agent follows one opinionated toolchain: uv for dependencies and virtual environments, ruff for both linting and formatting, ty for type checking, pytest for tests with coverage and prek for pre-commit hooks. Its rules include adding dependencies with uv add instead of editing pyproject.toml by hand, running commands through uv run rather than activating a virtualenv, and keeping dev dependencies in dependency groups.

A decision tree separates single-file scripts with inline dependencies from full projects. Reference notes cover pyproject layout, Ruff configuration, testing, security setup, Dependabot, uv commands and a migration checklist, and templates are provided for Dependabot and the pre-commit configuration. It targets modern Python, so it is not for projects that must support a version older than 3.11 or for teams that want to keep their legacy tools.

When your agent uses it

  • Creating a new Python package with a pyproject.toml
  • Writing a standalone script that needs external dependencies
  • Moving a project from Poetry or pip to uv
  • Replacing flake8, black and mypy with ruff and ty

Example prompts

  • “Set up a new Python package for our CLI with uv, ruff and pytest.”
  • “Migrate this repo from Poetry and black to uv and ruff.”
  • “Write a one-file script that fetches a URL and prints its title, with the dependencies declared inline.”
  • “Add prek pre-commit hooks and a Dependabot config to this project.”

Requirements

  • uv
  • Python 3.11 or newer

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Create Project Structure
  2. Configure pyproject.toml
  3. Install Dependencies
  4. Add Makefile

What it can do on your machine

Read from SKILL.md and the folder at commit 82fe822. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • uv
    • uvx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • httpbin.org

    Also links to:

    • github.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Modern Python Tooling loads about 2.5k tokens when it runs, and up to ~13k if it reads all its reference files. Until then it costs about 43 tokens; SKILL.md has 755 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~43
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~13k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from trailofbits/skills at commit 82fe822, republished under its CC-BY-SA-4.0 licence (© trailofbits). 755 words, ~2,482 tokens.

Download SKILL.mdSave it as .claude/skills/modern-python/SKILL.md (or your agent's skills folder). This skill also uses 13 other files; get the full folder from GitHub.
name
modern-python
description
Configures Python projects with modern tooling (uv, ruff, ty). Use when creating projects, writing standalone scripts, or migrating from pip/Poetry/mypy/black.

Modern Python

Guide for modern Python tooling and best practices, based on trailofbits/cookiecutter-python.

When to Use This Skill

  • Creating a new Python project or package
  • Setting up pyproject.toml configuration
  • Configuring development tools (linting, formatting, testing)
  • Writing Python scripts with external dependencies
  • Migrating from legacy tools (when user requests it)

When NOT to Use This Skill

  • User wants to keep legacy tooling: Respect existing workflows if explicitly requested
  • Python < 3.11 required: These tools target modern Python
  • Non-Python projects: Mixed codebases where Python isn't primary

Anti-Patterns to Avoid

AvoidUse Instead
[tool.ty] python-version[tool.ty.environment] python-version
uv pip installuv add and uv sync
Editing pyproject.toml manually to add depsuv add <pkg> / uv remove <pkg>
hatchling build backenduv_build (simpler, sufficient for most cases)
Poetryuv (faster, simpler, better ecosystem integration)
requirements.txtPEP 723 for scripts, pyproject.toml for projects
mypy / pyrightty (faster, from Astral team)
[project.optional-dependencies] for dev tools[dependency-groups] (PEP 735)
Manual virtualenv activation (source .venv/bin/activate)uv run <cmd>
pre-commitprek (faster, no Python runtime needed)

Key principles:

  • Always use uv add and uv remove to manage dependencies
  • Never manually activate or manage virtual environments—use uv run for all commands
  • Use [dependency-groups] for dev/test/docs dependencies, not [project.optional-dependencies]

Decision Tree

What are you doing?
│
├─ Single-file script with dependencies?
│   └─ Use PEP 723 inline metadata (./references/pep723-scripts.md)
│
├─ New multi-file project (not distributed)?
│   └─ Minimal uv setup (see Quick Start below)
│
├─ New reusable package/library?
│   └─ Full project setup (see Full Setup below)
│
└─ Migrating existing project?
    └─ See Migration Guide below

Tool Overview

ToolPurposeReplaces
uvPackage/dependency managementpip, virtualenv, pip-tools, pipx, pyenv
ruffLinting AND formattingflake8, black, isort, pyupgrade, pydocstyle
tyType checkingmypy, pyright (faster alternative)
pytestTesting with coverageunittest
prekPre-commit hooks (setup)pre-commit (faster, Rust-native)
Security Tools
ToolPurposeWhen It Runs
shellcheckShell script lintingpre-commit
detect-secretsSecret detectionpre-commit
actionlintWorkflow syntax validationpre-commit, CI
zizmorWorkflow security auditpre-commit, CI
pip-auditDependency vulnerability scanningCI, manual
DependabotAutomated dependency updatesscheduled

See security-setup.md for configuration and usage.

Quick Start: Minimal Project

For simple multi-file projects not intended for distribution:

bash
# Create project with uv
uv init myproject
cd myproject

# Add dependencies
uv add requests rich

# Add dev dependencies
uv add --group dev pytest ruff ty

# Run code
uv run python src/myproject/main.py

# Run tools
uv run pytest
uv run ruff check .

Full Project Setup

If starting from scratch, ask the user if they prefer to use the Trail of Bits cookiecutter template to bootstrap a complete project with already preconfigured tooling.

bash
uvx cookiecutter gh:trailofbits/cookiecutter-python
1. Create Project Structure
bash
uv init --package myproject
cd myproject

This creates:

myproject/
├── pyproject.toml
├── README.md
├── src/
│   └── myproject/
│       └── __init__.py
└── .python-version
2. Configure pyproject.toml

See pyproject.md for complete configuration reference.

Key sections:

toml
[project]
name = "myproject"
version = "0.1.0"
requires-python = ">=3.11"
dependencies = []

[dependency-groups]
dev = [{include-group = "lint"}, {include-group = "test"}, {include-group = "audit"}]
lint = ["ruff", "ty"]
test = ["pytest", "pytest-cov"]
audit = ["pip-audit"]

[tool.ruff]
line-length = 100
target-version = "py311"

[tool.ruff.lint]
select = ["ALL"]
ignore = ["D", "COM812", "ISC001"]

[tool.pytest]
addopts = ["--cov=myproject", "--cov-fail-under=80"]

[tool.ty.terminal]
error-on-warning = true

[tool.ty.environment]
python-version = "3.11"

[tool.ty.rules]
# Strict from day 1 for new projects
possibly-unresolved-reference = "error"
unused-ignore-comment = "warn"
3. Install Dependencies
bash
# Install all dependency groups
uv sync --all-groups

# Or install specific groups
uv sync --group dev
4. Add Makefile
makefile
.PHONY: dev lint format test build

dev:
	uv sync --all-groups

lint:
	uv run ruff format --check && uv run ruff check && uv run ty check src/

format:
	uv run ruff format .

test:
	uv run pytest

build:
	uv build

Migration Guide

When a user requests migration from legacy tooling:

From requirements.txt + pip

First, determine the nature of the code:

For standalone scripts: Convert to PEP 723 inline metadata (see pep723-scripts.md)

For projects:

bash
# Initialize uv in existing project
uv init --bare

# Add dependencies using uv (not by editing pyproject.toml)
uv add requests rich  # add each package

# Or import from requirements.txt (review each package before adding)
# Note: Complex version specifiers may need manual handling
grep -v '^#' requirements.txt | grep -v '^-' | grep -v '^\s*$' | while read -r pkg; do
    uv add "$pkg" || echo "Failed to add: $pkg"
done

uv sync

Then:

  1. Delete requirements.txt, requirements-dev.txt
  2. Delete virtual environment (venv/, .venv/)
  3. Add uv.lock to version control
From setup.py / setup.cfg
  1. Run uv init --bare to create pyproject.toml
  2. Use uv add to add each dependency from install_requires
  3. Use uv add --group dev for dev dependencies
  4. Copy non-dependency metadata (name, version, description, etc.) to [project]
  5. Delete setup.py, setup.cfg, MANIFEST.in
Show full SKILL.md (310 more words)Show less
From flake8 + black + isort
  1. Remove flake8, black, isort via uv remove
  2. Delete .flake8, pyproject.toml [tool.black], [tool.isort] configs
  3. Add ruff: uv add --group dev ruff
  4. Add ruff configuration (see ruff-config.md)
  5. Run uv run ruff check --fix . to apply fixes
  6. Run uv run ruff format . to format
From mypy / pyright
  1. Remove mypy/pyright via uv remove
  2. Delete mypy.ini, pyrightconfig.json, or [tool.mypy]/[tool.pyright] sections
  3. Add ty: uv add --group dev ty
  4. Run uv run ty check src/

Quick Reference: uv Commands

CommandDescription
uv initCreate new project
uv init --packageCreate distributable package
uv add <pkg>Add dependency
uv add --group dev <pkg>Add to dependency group
uv remove <pkg>Remove dependency
uv syncInstall dependencies
uv sync --all-groupsInstall all dependency groups
uv run <cmd>Run command in venv
uv run --with <pkg> <cmd>Run with temporary dependency
uv buildBuild package
uv publishPublish to PyPI
Ad-hoc Dependencies with --with

Use uv run --with for one-off commands that need packages not in your project:

bash
# Run Python with a temporary package
uv run --with requests python -c "import requests; print(requests.get('https://httpbin.org/ip').json())"

# Run a module with temporary deps
uv run --with rich python -m rich.progress

# Multiple packages
uv run --with requests --with rich python script.py

# Combine with project deps (adds to existing venv)
uv run --with httpx pytest  # project deps + httpx

When to use --with vs uv add:

  • uv add: Package is a project dependency (goes in pyproject.toml/uv.lock)
  • --with: One-off usage, testing, or scripts outside a project context

See uv-commands.md for complete reference.

Quick Reference: Dependency Groups

toml
[dependency-groups]
dev = ["ruff", "ty"]
test = ["pytest", "pytest-cov", "hypothesis"]
docs = ["sphinx", "myst-parser"]

Install with: uv sync --group dev --group test

Best Practices Checklist

  • Use src/ layout for packages
  • Set requires-python = ">=3.11"
  • Configure ruff with select = ["ALL"] and explicit ignores
  • Use ty for type checking
  • Enforce test coverage minimum (80%+)
  • Use dependency groups instead of extras for dev tools
  • Add uv.lock to version control
  • Use PEP 723 for standalone scripts

© trailofbits, CC-BY-SA-4.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 13 other files (references, assets) in plugins/modern-python/skills/modern-python of trailofbits/skills.

  • SKILL.md
  • agents/openai.yaml
  • assets/trail-of-bits-mark.svg
  • references/dependabot.md
  • references/migration-checklist.md
  • references/pep723-scripts.md
  • references/prek.md
  • references/pyproject.md
  • references/ruff-config.md
  • references/security-setup.md
  • references/testing.md
  • references/uv-commands.md
  • templates/dependabot.yml
  • templates/pre-commit-config.yaml

Open the folder on GitHubat commit 82fe822

Compare with similar skills

Modern Python Tooling next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Modern Python Tooling compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Modern Python Tooling this skilltrailofbits/skills7.4k—~2.5kAutomated safety check: PassCC-BY-SA-4.0
Modern Python ToolchainXiaomiMiMo/MiMo-Code14k—~1.5kAutomated safety check: NotesMIT
Kedro Babysitkedro-org/kedro11k—~4kAutomated safety check: PassCustom licence
Cb Code QualityBlkLeg/CircuitBreaker201—~1.9kAutomated safety check: PassMIT
Python ProJeffallan/claude-skills12k—~1.6kAutomated safety check: PassMIT
Modern Pythonantoinebou12/uml-mcp105—~1kAutomated safety check: PassMIT

Similar skills

  • Modern Python Toolchain

    XiaomiMiMo/MiMo-Code

    Sets up Python projects with uv for packages and environments, ruff for linting and formatting, and pyright for type checking, with rules for running everything through uv.

    14k GitHub stars~1.5k tokensUpdated 4 days ago
    DevelopmentAuto-check: notes
  • Kedro Babysit

    kedro-org/kedro

    Run Kedro's local lint / format / type-check / tests on changed files (uses the project's pre-commit hooks, ruff, mypy, pytest, lint-imports, detect-secrets, Make targets — in the right venv), or…

    11k GitHub stars~4k tokensUpdated today
    DevelopmentAuto-check passed
  • Cb Code Quality

    BlkLeg/CircuitBreaker

    Circuit Breaker code conventions and the quality gates that actually block a push — ruff, mypy, eslint, the pytest coverage ratchet, and the make verify tiers.

    201 GitHub stars~1.9k tokensUpdated 2 days ago
    DevelopmentAuto-check passed
  • Python Pro

    Jeffallan/claude-skills

    Writes type-annotated Python 3.11+ with async patterns, dataclasses and pytest suites, validated with mypy in strict mode, black and ruff.

    12k GitHub stars~1.6k tokensUpdated 4 days ago
    DevelopmentAuto-check passed
  • Modern Python

    antoinebou12/uml-mcp

    Modern Python tooling and best practices using uv, ruff, ty, and pytest.

    105 GitHub stars~1k tokensUpdated today
    DevelopmentAuto-check passed
  • Specx Project Tooling

    maksimzayats/specx

    Add strict Python project tooling for a specx service. An agent skill from maksimzayats/specx.

    202 GitHub stars~965 tokensUpdated 2 mo ago
    DevelopmentAuto-check passed

More from trailofbits/skills

All 79 skills in this repo
  • Code Graph Mermaid Diagrams

    trailofbits/skills

    Official

    Generates Mermaid diagrams from Trailmark code graphs, including call graphs, class hierarchies, module dependency maps, complexity heatmaps and attack surface data flows.

    7.4k GitHub starsUsed in 1 repo~1.7k tokens
    Auto-check passed
  • CodeQL Security Scan

    trailofbits/skills

    Official

    Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.

    7.4k GitHub stars~4.6k tokensUpdated today
    Auto-check: notes
  • Trailmark Graph Evolution

    trailofbits/skills

    Official

    Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.

    7.4k GitHub stars~3.4k tokensUpdated today
    Auto-check passed
  • Let Fate Decide

    trailofbits/skills

    Official

    Draws a 12 Houses tarot spread to break ties when a request is vague or casually delegated, then reads the cards to pick the next step.

    7.4k GitHub stars~2.5k tokensUpdated today
    Auto-check: notes
  • Burp Suite Project Parser

    trailofbits/skills

    Official

    Searches and extracts data from Burp Suite project files on the command line: regex searches over responses, audit findings, proxy history and site map data.

    7.4k GitHub starsUsed in 4 repos~4.2k tokens
    Auto-check: notes
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.4k GitHub stars~3.7k tokensUpdated today
    Auto-check: notes

Categories

Questions about Modern Python Tooling

What does Modern Python Tooling do?

Sets up Python projects and standalone scripts with uv, ruff, ty, pytest and prek, and helps move existing projects off pip, Poetry, mypy and black. The agent follows one opinionated toolchain: uv for dependencies and virtual environments, ruff for both linting and formatting, ty for type checking, pytest for tests with coverage and prek for pre-commit hooks.toml by hand, running commands through uv run rather than activating a virtualenv, and keeping dev dependencies in dependency groups.

When should I use Modern Python Tooling?

Modern Python Tooling fits situations like: creating a new Python package with a pyproject.toml; writing a standalone script that needs external dependencies; moving a project from Poetry or pip to uv; replacing flake8, black and mypy with ruff and ty.

How do I install Modern Python Tooling in Claude Code?

Run `npx skills add trailofbits/skills --skill modern-python -a claude-code`. Or copy the skill folder (plugins/modern-python/skills/modern-python in trailofbits/skills) into .claude/skills/modern-python in your project. Claude Code loads it when a task matches its description.

How do I install Modern Python Tooling in Codex?

Run `npx skills add trailofbits/skills --skill modern-python -a codex`. Or copy the skill folder (plugins/modern-python/skills/modern-python in trailofbits/skills) into .agents/skills/modern-python in your project. Codex loads it when a task matches its description.

Can I use Modern Python Tooling in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trailofbits/skills --skill modern-python -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/modern-python, .gemini/skills/modern-python, .github/skills/modern-python and .opencode/skills/modern-python in your project.

What does Modern Python Tooling need to run?

Going by SKILL.md and its folder, Modern Python Tooling needs the command-line tools its instructions call (uv and uvx). Our summary lists: uv; Python 3.11 or newer.

Does Modern Python Tooling access the network?

SKILL.md names 2 domains. In commands or code: httpbin.org; the agent is likely to contact it when it follows the instructions. As links in the text: github.com. This is read from the text; nothing was executed.

Is Modern Python Tooling safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Modern Python Tooling use?

Modern Python Tooling is published under the CC-BY-SA-4.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Modern Python Tooling use?

About 2.5k tokens (SKILL.md is roughly 9.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 11k tokens, read only when the agent opens those files.

What are the alternatives to Modern Python Tooling?

Skills that share tags, products or a category with Modern Python Tooling: Modern Python Toolchain (XiaomiMiMo/MiMo-Code, 14k stars), Kedro Babysit (kedro-org/kedro, 11k stars), Cb Code Quality (BlkLeg/CircuitBreaker, 201 stars) and Python Pro (Jeffallan/claude-skills, 12k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Modern Python Tooling?

trailofbits (a GitHub organization, an official publisher) maintains it in trailofbits/skills, which has 7,420 GitHub stars. The repository holds 79 skills in this directory. The repository was last updated on October 7, 2026.

Source: trailofbits/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.