Python Security
Priority: P0 (CRITICAL)
Rules
- Keep secrets in env or secret stores; never hardcode them in code or fixtures.
- Parameterize SQL and validate file or path inputs before use.
- Prefer
subprocess.run([...], shell=False)with explicit args. - Audit dependency surfaces and keep security gates current.
Recipe
- Classify inputs: trusted config, semi-trusted runtime data, untrusted user or PR text.
- Validate or normalize before boundary calls.
- Redact secrets from logs, reports, and artifacts.
- Use least-privilege filesystem and process execution.
- Run dependency/security verification after auth or gate changes.
Anti-Patterns
- No shell string execution for user-shaped input.
- No secrets in example configs, tests, or docs.
- No direct path joins from untrusted input without root checks.
- No "internal-only" exception to SQL or subprocess hygiene.