Modern Python
Modern Python best practices. Use when creating new Python projects, and writing Python scripts, or migrating existing projects from legacy tools.
- Type
- Plugin
- Repository
- trailofbits/skills
- GitHub stars
- 7.3k
- License
- CC-BY-SA-4.0
- Repo last updated
- Sep 25, 2026
- Source file
- plugins/modern-python/.claude-plugin/plugin.json
- Version
- 1.6.2
- Author
- William Tan
What Modern Python is
Modern Python is a plugin published in the trailofbits/skills repository on GitHub, which has about 7.3k stars. The repository describes itself as: “Trail of Bits Claude Code skills for security research, vulnerability detection, and audit workflows”
A plugin is a package that bundles skills, slash commands, subagents, hooks, and MCP connectors so they install together. Plugins are plain files with a manifest at .claude-plugin/plugin.json, and they work in both Claude Code and Claude Cowork.
Installing Modern Python adds everything it ships in one step. Connectors inside a plugin still need to be connected separately, and hooks and subagents only run in Cowork and Claude Code, not in regular chat.
How to install Modern Python
Claude Code
- Add the repository as a plugin marketplace: claude plugin marketplace add trailofbits/skills
- Install the plugin: claude plugin install modern-python@<marketplace-name>, using the marketplace name from the repository's .claude-plugin/marketplace.json.
- Restart the session if the new skills or commands don't appear straight away.
Claude Cowork
- Open Customize → Plugins and choose Add marketplace.
- Enter trailofbits/skills (the owner/repo shorthand works for GitHub).
- Find Modern Python in the list, click Install, then connect any connectors it needs from its Connectors tab.
New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.
Inside the source file
An excerpt from plugins/modern-python/.claude-plugin/plugin.json, shared under the repository's CC-BY-SA-4.0 license. Read the full file on GitHub.
Modern Python tooling and best practices using uv, ruff, ty, and pytest. Based on patterns from trailofbits/cookiecutter-python.
Author: William Tan
When to Use
- Setting up a new Python project with modern, fast tooling
- Replacing pip/virtualenv with uv for faster dependency management
- Replacing flake8/black/isort with ruff for unified linting and formatting
- Replacing mypy with ty for faster type checking
- Adding pre-commit hooks and security scanning to an existing project
What It Covers
Core Tools:
- uv - Package/dependency management (replaces pip, virtualenv, pip-tools, pipx, pyenv)
- ruff - Linting and formatting (replaces flake8, black, isort, pyupgrade)
- ty - Type checking (replaces mypy, pyright)
- pytest - Testing with coverage enforcement
- prek - Pre-commit hooks (replaces pre-commit)
Security Tools:
- shellcheck - Shell script linting
- detect-secrets - Secret detection in commits
- actionlint - GitHub Actions syntax validation
- zizmor - GitHub Actions security audit
- pip-audit - Dependency vulnerability scanning
- Dependabot - Automated dependency updates with supply chain protection
Standards:
- pyproject.toml - Single configuration file with dependency groups (PEP 735)
- PEP 723 - Inline script metadata for single-file scripts
- src/ layout - Standard package structure
- Python 3.11+ - Minimum version requirement
Hook: Legacy Command Interception
This plugin includes a SessionStart hook that prepends PATH shims for python, pip, pipx, and uv. When Claude runs a bare python, pip, or pipx command, the shell resolves to the shim, which prints an error with the correct uv alternative and exits non-zero. The suggested alternative always uses the exact command name python (never python3) so it also works outside a project; see the header comment in hooks/shims/python for the full rationale.
The shims sit on PATH, so they see every subprocess a tool spawns, not only what Claude types. That is why the intercepted set is narrow: it covers the invocations uv run and uv add genuinely replace, and passes the rest through to the real binary. python -c, python -m and python - read a program from the command line, an installed module, or stdin, so none of them resolves a script against a project's dependencies; uv pip carrying --project, --directory or --target is a tool building an environment it owns. Redirecting those broke real tooling, including prek hook installation and any script piping into python3 - (#207).
Commands like grep python, which python, and cat python.txt work normally because python is a shell argument, not the command being invoked.
Installation
/plugin install trailofbits/skills/plugins/modern-python Before you install
- Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
- Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
- Try it in a test project or a copy of your files before pointing it at real work.
- Pin the version you tested, and review changes before updating.
- Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.
FAQ
What is Modern Python?
Modern Python is a plugin for Claude Code and Claude Cowork from the trailofbits/skills repository on GitHub. Modern Python best practices. Use when creating new Python projects, and writing Python scripts, or migrating existing projects from legacy tools.
How do I install Modern Python in Claude Code?
Add the repository as a plugin marketplace: claude plugin marketplace add trailofbits/skills Install the plugin: claude plugin install modern-python@<marketplace-name>, using the marketplace name from the repository's .claude-plugin/marketplace.json. Restart the session if the new skills or commands don't appear straight away.
Can I use Modern Python in Claude Cowork?
Open Customize → Plugins and choose Add marketplace. Enter trailofbits/skills (the owner/repo shorthand works for GitHub). Find Modern Python in the list, click Install, then connect any connectors it needs from its Connectors tab.
Is Modern Python safe to install?
It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.
Similar resources
- Fp Check Systematic false positive verification for security bug analysis with mandatory gate reviews Plugin · trailofbits/skills
- Draw Draw the 12 Houses of the Zodiac Tarot spread and return a concise structured reading. Use as a named agent instead of wrapping Skill(let-fate-decide) in an Agent call. Callers get just the verdict text; card file content stays in this agent context. Subagent · trailofbits/skills
- Function Analyzer Analyzes one function in depth for audit context: invariants, assumptions, and what its callees establish. Writes the prose analysis to disk and returns a compact record. Use for dense functions, data-flow chains, cryptographic code, and state machines. Subagent · trailofbits/skills
- Gh Cli Intercepts GitHub URL fetches (WebFetch and MCP fetch tools) and curl/wget commands, redirecting to the authenticated gh CLI. Plugin · trailofbits/skills
- Mutation Testing Configures mewt or muton campaigns, analyzes surviving mutants, and investigates bugs exposed by testing gaps. Use when setting up mutation testing, reviewing campaign results, identifying equivalent mutants, or finding bugs from surviving mutations. Plugin · trailofbits/skills
- Let Fate Decide Draws the 12 Houses of the Zodiac Tarot spread using cryptographic randomness to add 100+ bits of entropy to vague or underspecified planning. Interprets the spread to guide next steps. Use when feeling lucky, invoking heart-of-the-cards energy, or when prompts are ambiguous. Plugin · trailofbits/skills
- Property Based Testing Write, review, and triage property-based tests — Hypothesis, fast-check, proptest, and Echidna or Medusa for Solidity invariants Plugin · trailofbits/skills
- Insecure Defaults Detects insecure default configurations including hardcoded credentials, fallback secrets, weak authentication defaults, and dangerous values in production Plugin · trailofbits/skills