Modern Python Toolchain
XiaomiMiMo/MiMo-Code
Sets up Python projects with uv for packages and environments, ruff for linting and formatting, and pyright for type checking, with rules for running everything through uv.
Sets up Python projects and standalone scripts with uv, ruff, ty, pytest and prek, and helps move existing projects off pip, Poetry, mypy and black.
$ npx skills add trailofbits/skills --skill modern-python -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install trailofbits/skills modern-python --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/modern-python/skills/modern-python .claude/skills/modern-python && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "modern-python" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/modern-python/skills/modern-python into .claude/skills/modern-python/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "modern-python", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/trailofbits/skills/tree/main/plugins/modern-python/skills/modern-pythonType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add trailofbits/skills --skill modern-python -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install trailofbits/skills modern-python --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/modern-python/skills/modern-python .agents/skills/modern-python && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "modern-python" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/modern-python/skills/modern-python into .agents/skills/modern-python/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "modern-python", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trailofbits/skills --skill modern-python -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install trailofbits/skills modern-python --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/modern-python/skills/modern-python .cursor/skills/modern-python && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "modern-python" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/modern-python/skills/modern-python into .cursor/skills/modern-python/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "modern-python", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/trailofbits/skills.git --path plugins/modern-python/skills/modern-python--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add trailofbits/skills --skill modern-python -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install trailofbits/skills modern-python --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/modern-python/skills/modern-python .gemini/skills/modern-python && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "modern-python" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/modern-python/skills/modern-python into .gemini/skills/modern-python/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "modern-python", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install trailofbits/skills modern-pythonInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add trailofbits/skills --skill modern-python -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/modern-python/skills/modern-python .github/skills/modern-python && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "modern-python" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/modern-python/skills/modern-python into .github/skills/modern-python/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "modern-python", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trailofbits/skills --skill modern-python -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install trailofbits/skills modern-python --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/modern-python/skills/modern-python .opencode/skills/modern-python && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "modern-python" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/modern-python/skills/modern-python into .opencode/skills/modern-python/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "modern-python", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
modern-pythonSets up Python projects and standalone scripts with uv, ruff, ty, pytest and prek, and helps move existing projects off pip, Poetry, mypy and black.
The agent follows one opinionated toolchain: uv for dependencies and virtual environments, ruff for both linting and formatting, ty for type checking, pytest for tests with coverage and prek for pre-commit hooks. Its rules include adding dependencies with uv add instead of editing pyproject.toml by hand, running commands through uv run rather than activating a virtualenv, and keeping dev dependencies in dependency groups.
A decision tree separates single-file scripts with inline dependencies from full projects. Reference notes cover pyproject layout, Ruff configuration, testing, security setup, Dependabot, uv commands and a migration checklist, and templates are provided for Dependabot and the pre-commit configuration. It targets modern Python, so it is not for projects that must support a version older than 3.11 or for teams that want to keep their legacy tools.
4 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 82fe822. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
uvuvxFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
httpbin.orgAlso links to:
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Modern Python Tooling loads about 2.5k tokens when it runs, and up to ~13k if it reads all its reference files. Until then it costs about 43 tokens; SKILL.md has 755 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from trailofbits/skills at commit 82fe822, republished under its CC-BY-SA-4.0 licence (© trailofbits). 755 words, ~2,482 tokens.
.claude/skills/modern-python/SKILL.md (or your agent's skills folder). This skill also uses 13 other files; get the full folder from GitHub.Guide for modern Python tooling and best practices, based on trailofbits/cookiecutter-python.
pyproject.toml configuration| Avoid | Use Instead |
|---|---|
[tool.ty] python-version | [tool.ty.environment] python-version |
uv pip install | uv add and uv sync |
| Editing pyproject.toml manually to add deps | uv add <pkg> / uv remove <pkg> |
hatchling build backend | uv_build (simpler, sufficient for most cases) |
| Poetry | uv (faster, simpler, better ecosystem integration) |
| requirements.txt | PEP 723 for scripts, pyproject.toml for projects |
| mypy / pyright | ty (faster, from Astral team) |
[project.optional-dependencies] for dev tools | [dependency-groups] (PEP 735) |
Manual virtualenv activation (source .venv/bin/activate) | uv run <cmd> |
| pre-commit | prek (faster, no Python runtime needed) |
Key principles:
uv add and uv remove to manage dependenciesuv run for all commands[dependency-groups] for dev/test/docs dependencies, not [project.optional-dependencies]What are you doing?
│
├─ Single-file script with dependencies?
│ └─ Use PEP 723 inline metadata (./references/pep723-scripts.md)
│
├─ New multi-file project (not distributed)?
│ └─ Minimal uv setup (see Quick Start below)
│
├─ New reusable package/library?
│ └─ Full project setup (see Full Setup below)
│
└─ Migrating existing project?
└─ See Migration Guide below| Tool | Purpose | Replaces |
|---|---|---|
| uv | Package/dependency management | pip, virtualenv, pip-tools, pipx, pyenv |
| ruff | Linting AND formatting | flake8, black, isort, pyupgrade, pydocstyle |
| ty | Type checking | mypy, pyright (faster alternative) |
| pytest | Testing with coverage | unittest |
| prek | Pre-commit hooks (setup) | pre-commit (faster, Rust-native) |
| Tool | Purpose | When It Runs |
|---|---|---|
| shellcheck | Shell script linting | pre-commit |
| detect-secrets | Secret detection | pre-commit |
| actionlint | Workflow syntax validation | pre-commit, CI |
| zizmor | Workflow security audit | pre-commit, CI |
| pip-audit | Dependency vulnerability scanning | CI, manual |
| Dependabot | Automated dependency updates | scheduled |
See security-setup.md for configuration and usage.
For simple multi-file projects not intended for distribution:
# Create project with uv
uv init myproject
cd myproject
# Add dependencies
uv add requests rich
# Add dev dependencies
uv add --group dev pytest ruff ty
# Run code
uv run python src/myproject/main.py
# Run tools
uv run pytest
uv run ruff check .If starting from scratch, ask the user if they prefer to use the Trail of Bits cookiecutter template to bootstrap a complete project with already preconfigured tooling.
uvx cookiecutter gh:trailofbits/cookiecutter-pythonuv init --package myproject
cd myprojectThis creates:
myproject/
├── pyproject.toml
├── README.md
├── src/
│ └── myproject/
│ └── __init__.py
└── .python-versionSee pyproject.md for complete configuration reference.
Key sections:
[project]
name = "myproject"
version = "0.1.0"
requires-python = ">=3.11"
dependencies = []
[dependency-groups]
dev = [{include-group = "lint"}, {include-group = "test"}, {include-group = "audit"}]
lint = ["ruff", "ty"]
test = ["pytest", "pytest-cov"]
audit = ["pip-audit"]
[tool.ruff]
line-length = 100
target-version = "py311"
[tool.ruff.lint]
select = ["ALL"]
ignore = ["D", "COM812", "ISC001"]
[tool.pytest]
addopts = ["--cov=myproject", "--cov-fail-under=80"]
[tool.ty.terminal]
error-on-warning = true
[tool.ty.environment]
python-version = "3.11"
[tool.ty.rules]
# Strict from day 1 for new projects
possibly-unresolved-reference = "error"
unused-ignore-comment = "warn"# Install all dependency groups
uv sync --all-groups
# Or install specific groups
uv sync --group dev.PHONY: dev lint format test build
dev:
uv sync --all-groups
lint:
uv run ruff format --check && uv run ruff check && uv run ty check src/
format:
uv run ruff format .
test:
uv run pytest
build:
uv buildWhen a user requests migration from legacy tooling:
First, determine the nature of the code:
For standalone scripts: Convert to PEP 723 inline metadata (see pep723-scripts.md)
For projects:
# Initialize uv in existing project
uv init --bare
# Add dependencies using uv (not by editing pyproject.toml)
uv add requests rich # add each package
# Or import from requirements.txt (review each package before adding)
# Note: Complex version specifiers may need manual handling
grep -v '^#' requirements.txt | grep -v '^-' | grep -v '^\s*$' | while read -r pkg; do
uv add "$pkg" || echo "Failed to add: $pkg"
done
uv syncThen:
requirements.txt, requirements-dev.txtvenv/, .venv/)uv.lock to version controluv init --bare to create pyproject.tomluv add to add each dependency from install_requiresuv add --group dev for dev dependencies[project]setup.py, setup.cfg, MANIFEST.inuv remove.flake8, pyproject.toml [tool.black], [tool.isort] configsuv add --group dev ruffuv run ruff check --fix . to apply fixesuv run ruff format . to formatuv removemypy.ini, pyrightconfig.json, or [tool.mypy]/[tool.pyright] sectionsuv add --group dev tyuv run ty check src/| Command | Description |
|---|---|
uv init | Create new project |
uv init --package | Create distributable package |
uv add <pkg> | Add dependency |
uv add --group dev <pkg> | Add to dependency group |
uv remove <pkg> | Remove dependency |
uv sync | Install dependencies |
uv sync --all-groups | Install all dependency groups |
uv run <cmd> | Run command in venv |
uv run --with <pkg> <cmd> | Run with temporary dependency |
uv build | Build package |
uv publish | Publish to PyPI |
--withUse uv run --with for one-off commands that need packages not in your project:
# Run Python with a temporary package
uv run --with requests python -c "import requests; print(requests.get('https://httpbin.org/ip').json())"
# Run a module with temporary deps
uv run --with rich python -m rich.progress
# Multiple packages
uv run --with requests --with rich python script.py
# Combine with project deps (adds to existing venv)
uv run --with httpx pytest # project deps + httpxWhen to use --with vs uv add:
uv add: Package is a project dependency (goes in pyproject.toml/uv.lock)--with: One-off usage, testing, or scripts outside a project contextSee uv-commands.md for complete reference.
[dependency-groups]
dev = ["ruff", "ty"]
test = ["pytest", "pytest-cov", "hypothesis"]
docs = ["sphinx", "myst-parser"]Install with: uv sync --group dev --group test
src/ layout for packagesrequires-python = ">=3.11"select = ["ALL"] and explicit ignoresuv.lock to version control© trailofbits, CC-BY-SA-4.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 13 other files (references, assets) in plugins/modern-python/skills/modern-python of trailofbits/skills.
Open the folder on GitHubat commit 82fe822
Modern Python Tooling next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Modern Python Tooling this skilltrailofbits/skills | 7.4k | — | ~2.5k | Automated safety check: Pass | CC-BY-SA-4.0 | |
| Modern Python ToolchainXiaomiMiMo/MiMo-Code | 14k | — | ~1.5k | Automated safety check: Notes | MIT | |
| Kedro Babysitkedro-org/kedro | 11k | — | ~4k | Automated safety check: Pass | Custom licence | |
| Cb Code QualityBlkLeg/CircuitBreaker | 201 | — | ~1.9k | Automated safety check: Pass | MIT | |
| Python ProJeffallan/claude-skills | 12k | — | ~1.6k | Automated safety check: Pass | MIT | |
| Modern Pythonantoinebou12/uml-mcp | 105 | — | ~1k | Automated safety check: Pass | MIT |
XiaomiMiMo/MiMo-Code
Sets up Python projects with uv for packages and environments, ruff for linting and formatting, and pyright for type checking, with rules for running everything through uv.
kedro-org/kedro
Run Kedro's local lint / format / type-check / tests on changed files (uses the project's pre-commit hooks, ruff, mypy, pytest, lint-imports, detect-secrets, Make targets — in the right venv), or…
BlkLeg/CircuitBreaker
Circuit Breaker code conventions and the quality gates that actually block a push — ruff, mypy, eslint, the pytest coverage ratchet, and the make verify tiers.
Jeffallan/claude-skills
Writes type-annotated Python 3.11+ with async patterns, dataclasses and pytest suites, validated with mypy in strict mode, black and ruff.
antoinebou12/uml-mcp
Modern Python tooling and best practices using uv, ruff, ty, and pytest.
maksimzayats/specx
Add strict Python project tooling for a specx service. An agent skill from maksimzayats/specx.
trailofbits/skills
Generates Mermaid diagrams from Trailmark code graphs, including call graphs, class hierarchies, module dependency maps, complexity heatmaps and attack surface data flows.
trailofbits/skills
Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.
trailofbits/skills
Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.
trailofbits/skills
Draws a 12 Houses tarot spread to break ties when a request is vague or casually delegated, then reads the cards to pick the next step.
trailofbits/skills
Searches and extracts data from Burp Suite project files on the command line: regex searches over responses, audit findings, proxy history and site map data.
trailofbits/skills
Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.
Categories
Sets up Python projects and standalone scripts with uv, ruff, ty, pytest and prek, and helps move existing projects off pip, Poetry, mypy and black. The agent follows one opinionated toolchain: uv for dependencies and virtual environments, ruff for both linting and formatting, ty for type checking, pytest for tests with coverage and prek for pre-commit hooks.toml by hand, running commands through uv run rather than activating a virtualenv, and keeping dev dependencies in dependency groups.
Modern Python Tooling fits situations like: creating a new Python package with a pyproject.toml; writing a standalone script that needs external dependencies; moving a project from Poetry or pip to uv; replacing flake8, black and mypy with ruff and ty.
Run `npx skills add trailofbits/skills --skill modern-python -a claude-code`. Or copy the skill folder (plugins/modern-python/skills/modern-python in trailofbits/skills) into .claude/skills/modern-python in your project. Claude Code loads it when a task matches its description.
Run `npx skills add trailofbits/skills --skill modern-python -a codex`. Or copy the skill folder (plugins/modern-python/skills/modern-python in trailofbits/skills) into .agents/skills/modern-python in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trailofbits/skills --skill modern-python -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/modern-python, .gemini/skills/modern-python, .github/skills/modern-python and .opencode/skills/modern-python in your project.
Going by SKILL.md and its folder, Modern Python Tooling needs the command-line tools its instructions call (uv and uvx). Our summary lists: uv; Python 3.11 or newer.
SKILL.md names 2 domains. In commands or code: httpbin.org; the agent is likely to contact it when it follows the instructions. As links in the text: github.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Modern Python Tooling is published under the CC-BY-SA-4.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.5k tokens (SKILL.md is roughly 9.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 11k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Modern Python Tooling: Modern Python Toolchain (XiaomiMiMo/MiMo-Code, 14k stars), Kedro Babysit (kedro-org/kedro, 11k stars), Cb Code Quality (BlkLeg/CircuitBreaker, 201 stars) and Python Pro (Jeffallan/claude-skills, 12k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
trailofbits (a GitHub organization, an official publisher) maintains it in trailofbits/skills, which has 7,420 GitHub stars. The repository holds 79 skills in this directory. The repository was last updated on October 7, 2026.
Source: trailofbits/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.