django-verification

Pass

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: Executes a wide range of standard Django management commands and third-party developer tools including ruff, black, mypy, pytest, and npm to verify project state and build assets. It also uses python manage.py shell with heredocs and piped inputs to perform configuration checks and test data creation.
  • [DATA_EXFILTRATION]: Performs defensive scanning of the environment and repository for sensitive data, including checks for DJANGO_SECRET_KEY and the use of gitleaks to detect hardcoded credentials.
  • [PROMPT_INJECTION]: 1. Ingestion points: The skill analyzes untrusted local project files, configuration settings, and git diff outputs across multiple audit phases. 2. Boundary markers: Absent; project data is ingested directly by analysis tools without explicit delimiters or instructions for the agent to ignore embedded commands. 3. Capability inventory: The skill has the ability to execute shell commands, install packages, and read/write local files. 4. Sanitization: No explicit sanitization or validation of the audited project content is performed before processing.
  • [REMOTE_CODE_EXECUTION]: Recommends and performs the installation of well-known security and testing packages (e.g., bandit, safety, pip-audit, pytest-cov) from official registries.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 11, 2026, 03:42 AM
Security Audit — agent-trust-hub — django-verification