django-expert

Fail

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: CRITICALEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides a link to documentation hosted at https://jeffallan.github.io/claude-skills/skills/backend/django-expert/ which has been flagged as malicious and blacklisted by automated security scanners (URLite).- [COMMAND_EXECUTION]: The workflow involves the execution of shell commands such as manage.py makemigrations and manage.py migrate on the host system to manage database schema.- [INDIRECT_PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection attacks because it interprets complex user requirements without sufficient isolation or validation.- Ingestion points: Identification of project requirements, model designs, and API structures from user input.- Boundary markers: No explicit delimiters or warnings are used to prevent the agent from following instructions embedded within user-provided data.- Capability inventory: The agent is instructed to perform file operations (writing Python code) and execute local shell commands.- Sanitization: The skill lacks mechanisms to sanitize or filter user-provided data before it is processed into implementation tasks.
Recommendations
  • AI detected serious security threats
  • Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 6, 2026, 11:35 AM
Security Audit — agent-trust-hub — django-expert