django-security
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides documentation on defensive coding practices. It correctly advises on production settings (DEBUG=False, security headers), secure credential management via environment variables, and SQL/XSS prevention techniques.
- [INDIRECT_PROMPT_INJECTION]: The skill defines patterns for handling external user input in web views and templates. However, it incorporates robust mitigations including auto-escaping, CSRF tokens, and ORM parameterization.
- Ingestion points: User-supplied data processed by views and templates (e.g.,
user_input,email,username) and file uploads in SKILL.md. - Boundary markers: Django template auto-escaping,
{% csrf_token %}markers, andLoginRequiredMixinfor access control in SKILL.md. - Capability inventory: Database read/write operations through the Django ORM and file system access via
FileFieldandMEDIA_ROOTin SKILL.md. - Sanitization: Instructions include
escape(),format_html(),escapejs, and ORM-based query parameterization to prevent injection attacks.
Audit Metadata