django-verification

Fail

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: HIGHCREDENTIALS_UNSAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: Phase 6 contains a shell command that pipes hardcoded credentials ('admin@example.com' and 'admin') to create a Django superuser. This pattern presents a risk of default credentials being accidentally used in non-test environments.
  • [DYNAMIC_EXECUTION]: The skill employs dynamic script generation by piping Python code and using heredocs with python manage.py shell in Phases 6, 7, 9, and 10 to perform runtime environment and database checks.
  • [COMMAND_EXECUTION]: The workflow relies extensively on executing shell commands to interact with the environment, manage migrations, and run external binaries like ruff, bandit, and npm.
  • [INDIRECT_PROMPT_INJECTION]: The skill operates as a verification tool that ingests and processes untrusted code from a repository, creating a surface where malicious file content could influence agent output.
  • Ingestion points: Local repository files (Python code, templates, configuration) processed by linting and testing utilities.
  • Boundary markers: Absent; there are no specific delimiters to isolate external code from the agent's instructions.
  • Capability inventory: File system read/write, database management via Django commands, and shell execution.
  • Sanitization: Absent; tools process the project files directly as provided.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 1, 2026, 02:38 AM
Security Audit — agent-trust-hub — django-verification