django-security

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides documentation on defensive coding practices. It correctly advises on production settings (DEBUG=False, security headers), secure credential management via environment variables, and SQL/XSS prevention techniques.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines patterns for handling external user input in web views and templates. However, it incorporates robust mitigations including auto-escaping, CSRF tokens, and ORM parameterization.
  • Ingestion points: User-supplied data processed by views and templates (e.g., user_input, email, username) and file uploads in SKILL.md.
  • Boundary markers: Django template auto-escaping, {% csrf_token %} markers, and LoginRequiredMixin for access control in SKILL.md.
  • Capability inventory: Database read/write operations through the Django ORM and file system access via FileField and MEDIA_ROOT in SKILL.md.
  • Sanitization: Instructions include escape(), format_html(), escapejs, and ORM-based query parameterization to prevent injection attacks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 11:20 PM
Security Audit — agent-trust-hub — django-security