django-celery

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides patterns for background task execution where workers process data received from external message brokers, establishing a surface for indirect prompt injection.\n
  • Ingestion points: Task arguments defined in SKILL.md, such as user_id, contact_id, and order_id, which originate from application events and user actions.\n
  • Boundary markers: Absent; the templates do not include specific delimiters or instructions to ignore embedded commands within task data.\n
  • Capability inventory: Task examples include database write operations, network requests to external CRM and Email services, and file system access for PDF generation.\n
  • Sanitization: The provided examples rely on standard Django ORM lookups which validate primary key types but do not implement broader sanitization or validation of complex data payloads.\n- [SAFE]: The skill explicitly configures 'json' as the task serializer, which is a security best practice that prevents remote code execution vulnerabilities associated with Python's default pickle serialization.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:39 PM
Security Audit — agent-trust-hub — django-celery