django-expert

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides secure-by-default code templates for Django 5.0 and DRF. It explicitly mandates security best practices, including the use of environment variables for secrets, implementation of strict object-level permissions, and the avoidance of raw SQL.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a surface for indirect prompt injection as it processes user-provided source code and configuration files.
  • Ingestion points: The skill reads and analyzes Django project files such as models.py, serializers.py, and settings.py.
  • Boundary markers: No specific delimiters or boundary warnings are implemented for processing these files.
  • Capability inventory: The skill uses manage.py for migrations and curl for endpoint validation.
  • Sanitization: The skill instructions explicitly require input validation and the use of Django's built-in security features to mitigate risks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:48 PM
Security Audit — agent-trust-hub — django-expert