django-verification
Pass
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill instructions involve running standard development commands such as Django management commands, linters (ruff, black, isort), and test runners (pytest). These are necessary for the skill's stated purpose of project verification.
- [CREDENTIALS_UNSAFE]: The skill includes steps to verify the existence of sensitive environment variables like
DJANGO_SECRET_KEYand utilizesgitleaksto proactively search for hardcoded secrets. It also provides a template command for superuser creation which uses placeholder credentials. - [PROMPT_INJECTION]: The skill processes local source code and git diffs, representing an indirect prompt injection surface. However, this risk is mitigated by the skill's specific context as a developer utility.
- Ingestion points: Project source code, configuration files, and git diff output.
- Boundary markers: None.
- Capability inventory: Shell access for execution of linters, security scanners, and test suites.
- Sanitization: Not applicable, as the skill operates on the project's own code for auditing purposes.
Audit Metadata