python-project-workflow

A workflow for setting up, inspecting, preserving, and verifying Python project structure and automation. It covers packaging, dependencies, tooling, continuous integration, compatibility, and repository checks.

In plain words
What is it for?
Starting or maintaining Python projects, configuring packaging and dependencies, improving CI, checking compatibility, and running the repository's own validation commands.
Why use it?
It helps make project-wide Python changes without overlooking existing conventions or automation. It distinguishes established repositories from genuinely new projects before recommending setup work.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/codesigils/python-project-workflow-skill/python-project-workflow
Any agent
npx skills add CodeSigils/python-project-workflow-skill --skill python-project-workflow
Clone the repo
git clone --depth 1 https://github.com/CodeSigils/python-project-workflow-skill

Made for: Claude Code, Codex.

Per session 90 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 1,839 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00090 $0.01839
Opus 5 $0.00045 $0.00920
Sonnet 5 $0.00018 $0.00368
Haiku 4.5 $0.00009 $0.00184

Measured yesterday against content hash caa2ad7e8381, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

python-project-workflow scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

skills/python-project-workflow/SKILL.md · 194 lines

How it starts

The opening of the file, as written. The whole thing — 194 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Python Project Workflow

Apply a preservation-first workflow to Python project setup, tooling, CI, packaging, compatibility, and repository-wide verification.

Framework-specific project conventions are out of scope. For Django, FastAPI, Flask, and similar frameworks, use dedicated framework guidance or preserve the project's established workflow. Do not present this generic baseline as framework-complete guidance.

Workflow

  1. Inspect repository instructions, version-control state, and project-native configuration before recommending or making changes.
  2. Classify the repository and the requested operation.
  3. Load only the references relevant to that classification.
  4. Preserve coherent local conventions unless the user explicitly requests modernization.
  5. Verify with project-native gates and report actual results.

Repository Classification

Apply Existing and Automation before considering Greenfield. Missing packaging metadata or tests does not make a repository greenfield when meaningful source, scripts, documentation, or history already exist.

Signal Classification Guidance
Empty directory or explicit new-scaffold request Greenfield Load references/pyproject-template.md
Packaging metadata and coherent tooling Existing project Orient first, then load task-specific guidance
Python used for repository checkers or governance Mature automation Load references/mature-repo-preservation.md
Eval or benchmark runners Automation with benchmarks Also load references/eval-benchmark-hardening.md

For isolated support scripts that fall outside this skill's trigger, use repository-native instructions and focused checks. Do not infer correctness from classification alone.

Operation Modes

  • Inspect or advise: use read-only discovery. Do not install dependencies, synchronize environments, generate files, or edit configuration.
  • Implement: make only changes authorized by the user and preserve unrelated worktree changes.
  • Verify: run already-available project-native gates first. Treat setup or dependency installation as a separate step when it is required.
  • Bootstrap: create or replace project structure only for an explicit greenfield or modernization request.

Read the full file on GitHub · 194 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 194 lines · 90 tokens per session scan A caa2ad7e8381

Subscribe to this mod's changes

python-project-workflow is a skill published in the GitHub repository CodeSigils/python-project-workflow-skill (1 stars, last pushed 9d ago), licensed MIT. It adds 90 tokens to every session and 1,839 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

load-github-action-thread

Download retained Codex GitHub Action thread artifacts and load their rollout history into the local Codex app. Use when asked to open, load, import, resume, or inspect a Codex automation thread from a GitHub Actions run or a related GitHub issue or pull request.

astral-sh/uv · 62 tokens

software-certificate-skill

面向普通用户,从真实软件项目全自动生成中国软件著作权申请资料:一次收集登记事实,自动分析业务、选择可追溯源码、取得真实界面证据,生成申请表信息、规范黑白灰操作手册、代码前后30页或全部材料及真实 DOCX/PDF;内部验证、渲染、哈希与备份只进入系统临时运行区,项目最终仅保留正式资料。适配 Codex、Claude Code、Cursor、OpenCode、WorkBuddy、QoderWork、TraeWork 及支持 Agent Skills 或 AGENTS.md 的平台。用户提到软件著作权、软著申请资料、申请表、代码材料、操作手册或软著审查时使用。.

IvanCodesDev/software-certificate-skill · 170 tokens

aos-fatos

Skill para buscar e comentar as checagens de fatos mais recentes do portal Aos Fatos (aosfatos.org), filtrando por selo de veracidade (verdadeiro, falso, não é bem assim), formato de conteúdo, ano e/ou canal temático — combináveis entre si (ex: formato + ano + selo) — ou a partir da descrição livre de algo que a…

marioluciofjr/skills · 145 tokens

eeat-audit

Audita textos ou URLs de posts publicados segundo os parâmetros de E-E-A-T (Experience, Expertise, Authoritativeness, Trustworthiness) do Google e atribui uma nota de 0 a 5 a cada pilar, com nota global ponderada. Use esta skill SEMPRE que a pessoa usuária pedir para auditar, avaliar, analisar ou revisar um texto ou…

marioluciofjr/skills · 135 tokens

gerador-soul

Gera um arquivo SOUL.md completo e estruturado para qualquer agente ou assistente de IA. Use esta skill SEMPRE que a pessoa usuária quiser criar um SOUL.md, definir a identidade de um agente, descrever a "alma" de um assistente, ou usar os gatilhos "/soul", "/soul.md" ou "gerar soul". Ative também quando a pessoa…

marioluciofjr/skills · 155 tokens

craque-neto

Faz análise de risco de projetos gritando a real, sem bajulação, no tom de voz do ex-jogador José Ferreira Neto, o 'Craque Neto', apresentador do 'Donos da Bola' (Band) e da 'Rádio Craque Neto'. A resposta é só a bronca do Neto: texto corrido de até 200 palavras, primeira pessoa, linguagem do povo, palavrão pesado…

marioluciofjr/skills · 249 tokens