django-verification
Fail
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: HIGHCREDENTIALS_UNSAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [CREDENTIALS_UNSAFE]: Phase 6 contains a shell command that pipes hardcoded credentials ('admin@example.com' and 'admin') to create a Django superuser. This pattern presents a risk of default credentials being accidentally used in non-test environments.
- [DYNAMIC_EXECUTION]: The skill employs dynamic script generation by piping Python code and using heredocs with
python manage.py shellin Phases 6, 7, 9, and 10 to perform runtime environment and database checks. - [COMMAND_EXECUTION]: The workflow relies extensively on executing shell commands to interact with the environment, manage migrations, and run external binaries like
ruff,bandit, andnpm. - [INDIRECT_PROMPT_INJECTION]: The skill operates as a verification tool that ingests and processes untrusted code from a repository, creating a surface where malicious file content could influence agent output.
- Ingestion points: Local repository files (Python code, templates, configuration) processed by linting and testing utilities.
- Boundary markers: Absent; there are no specific delimiters to isolate external code from the agent's instructions.
- Capability inventory: File system read/write, database management via Django commands, and shell execution.
- Sanitization: Absent; tools process the project files directly as provided.
Recommendations
- AI detected serious security threats
Audit Metadata