python-architecture — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited python-architecture (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Modern Python application architecture following functional core / imperative shell pattern, Domain-Driven Design, and type-safe data modeling.
Separate pure business logic from side effects:
See references/functional-core.md for detailed patterns and examples.
Follow bottom-up dependency flow:
Router/Handler → Service → Repository → Entity → DatabaseEach layer depends only on layers below.
Responsibilities:
from dataclasses import dataclass
from uuid import UUID
from decimal import Decimal
@dataclass
class Order:
"""Entity - has identity and encapsulated behavior"""
id: UUID
customer_id: UUID
total: Decimal
status: str
def apply_discount(self, rate: Decimal) -> None:
"""Business rule - encapsulated in entity"""
if self.status == "pending":
self.total = self.total * (1 - rate)
@classmethod
def from_request(cls, req, customer_id: UUID) -> "Order":
"""Transform API request → entity"""
return cls(id=uuid4(), customer_id=customer_id, total=Decimal("0"), status="pending")
def to_response(self):
"""Transform entity → API response"""
return {"id": self.id, "total": self.total, "status": self.status}from dataclasses import dataclass
@dataclass(frozen=True)
class Money:
"""Value object - immutable, no identity"""
amount: Decimal
currency: str
def add(self, other: "Money") -> "Money":
if self.currency != other.currency:
raise ValueError("Cannot add different currencies")
return Money(self.amount + other.amount, self.currency)See references/ddd.md for aggregates, bounded contexts, and domain services.
Abstract storage behind interface:
from abc import ABC, abstractmethod
from typing import Optional
class OrderRepository(ABC):
"""Abstract repository - interface only"""
@abstractmethod
def get(self, order_id: UUID) -> Optional[Order]:
pass
@abstractmethod
def save(self, order: Order) -> None:
pass
class PostgresOrderRepository(OrderRepository):
"""Concrete implementation"""
def get(self, order_id: UUID) -> Optional[Order]:
record = self.session.get(OrderRecord, order_id)
return Order.from_record(record) if record else None
def save(self, order: Order) -> None:
record = order.to_record()
self.session.merge(record)
self.session.commit()from_request(), to_response(), from_record(), to_record()See references/data-modeling.md for validation patterns, Pydantic features, and transformation examples.
frozen=True❌ Anemic Domain Model - Entities with only getters/setters, all logic in services ❌ Transaction Script - All logic in service layer, entities just data ❌ Leaky Abstraction - Repository exposing database details ❌ God Object - Entity with too many responsibilities ❌ Mixed Concerns - Business logic calling IO directly
For detailed examples, patterns, and decision trees, see the reference materials:
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.