django-verification

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill generates and executes Python scripts at runtime by piping string templates and heredocs into the python manage.py shell command. This is used for several diagnostic tasks, including database index verification, configuration auditing, and logging connectivity tests.
  • [INDIRECT_PROMPT_INJECTION]: As a verification loop, the skill is designed to ingest and process a wide variety of project files (source code, tests, and configuration files). This creates a potential surface for indirect prompt injection if the agent encounters malicious instructions embedded in the repository it is auditing.
  • Ingestion points: The skill reads and processes all Python files, requirements files, and configuration data (like pyproject.toml) within the target repository.
  • Boundary markers: The instructions do not define strict boundaries or provide explicit 'ignore instructions' directives when the agent reads external file content.
  • Capability inventory: The environment allows for code execution through pytest and manage.py shell, as well as file modification through auto-formatting tools.
  • Sanitization: The skill does not validate or sanitize the repository content before passing it to the execution engines or reporting tools.
  • [EXTERNAL_DOWNLOADS]: The skill utilizes security tools like pip-audit, safety, and npm audit which communicate with official package registries to check for known vulnerabilities. Additionally, the Continuous Integration examples provided in the documentation suggest the installation of standard development and security packages from official Python and Node.js repositories.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:40 PM
Security Audit — agent-trust-hub — django-verification