django-expert
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides secure-by-default code templates for Django 5.0 and DRF. It explicitly mandates security best practices, including the use of environment variables for secrets, implementation of strict object-level permissions, and the avoidance of raw SQL.
- [INDIRECT_PROMPT_INJECTION]: The skill has a surface for indirect prompt injection as it processes user-provided source code and configuration files.
- Ingestion points: The skill reads and analyzes Django project files such as models.py, serializers.py, and settings.py.
- Boundary markers: No specific delimiters or boundary warnings are implemented for processing these files.
- Capability inventory: The skill uses manage.py for migrations and curl for endpoint validation.
- Sanitization: The skill instructions explicitly require input validation and the use of Django's built-in security features to mitigate risks.
Audit Metadata