No. Interpolating user_input into a shell command with shell=True enables command injection. Use an explicit argument list such as subprocess.run(["git", "show", user_input], shell=False, check=True, ...), validate the allowed revision format, and avoid exposing secrets in errors or logs.
Scanned 9/5/2026
Install to Claude Code
npx -y skills add HoangNguyen0403/agent-skills-standard --skill python-security --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Python Security?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/hoangnguyen0403-python-security)More formats (shields.io, HTML) on the badges page.
No. Interpolating user_input into a shell command with shell=True enables command injection. Use an explicit argument list such as subprocess.run(["git", "show", user_input], shell=False, check=True, ...), validate the allowed revision format, and avoid exposing secrets in errors or logs.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!