For more context: this kind of work could fit nicely into the malware auditing system that was designed and implemented as part of the RFI that the blog author originally linked to[1].
Most of the infrastructure on the PyPI side is in place[2], but the current checks are mostly proofs of concept/exercises of the new APIs to ensure that they don't atrophy.
[1]: https://discuss.python.org/t/what-methods-should-we-implemen...
[2]: https://github.com/pypa/warehouse/tree/master/warehouse/malw...