django-expert
Fail
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: CRITICALEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill provides a link to documentation hosted at
https://jeffallan.github.io/claude-skills/skills/backend/django-expert/which has been flagged as malicious and blacklisted by automated security scanners (URLite).- [COMMAND_EXECUTION]: The workflow involves the execution of shell commands such asmanage.py makemigrationsandmanage.py migrateon the host system to manage database schema.- [INDIRECT_PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection attacks because it interprets complex user requirements without sufficient isolation or validation.- Ingestion points: Identification of project requirements, model designs, and API structures from user input.- Boundary markers: No explicit delimiters or warnings are used to prevent the agent from following instructions embedded within user-provided data.- Capability inventory: The agent is instructed to perform file operations (writing Python code) and execute local shell commands.- Sanitization: The skill lacks mechanisms to sanitize or filter user-provided data before it is processed into implementation tasks.
Recommendations
- AI detected serious security threats
- Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata