django-verification
Pass
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATIONPROMPT_INJECTIONREMOTE_CODE_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: Executes a wide range of standard Django management commands and third-party developer tools including
ruff,black,mypy,pytest, andnpmto verify project state and build assets. It also usespython manage.py shellwith heredocs and piped inputs to perform configuration checks and test data creation. - [DATA_EXFILTRATION]: Performs defensive scanning of the environment and repository for sensitive data, including checks for
DJANGO_SECRET_KEYand the use ofgitleaksto detect hardcoded credentials. - [PROMPT_INJECTION]: 1. Ingestion points: The skill analyzes untrusted local project files, configuration settings, and git diff outputs across multiple audit phases. 2. Boundary markers: Absent; project data is ingested directly by analysis tools without explicit delimiters or instructions for the agent to ignore embedded commands. 3. Capability inventory: The skill has the ability to execute shell commands, install packages, and read/write local files. 4. Sanitization: No explicit sanitization or validation of the audited project content is performed before processing.
- [REMOTE_CODE_EXECUTION]: Recommends and performs the installation of well-known security and testing packages (e.g.,
bandit,safety,pip-audit,pytest-cov) from official registries.
Audit Metadata