django-expert

Fail

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: CRITICALEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill includes a reference to a documentation URL (https://jeffallan.github.io/claude-skills/skills/backend/django-expert/) that is explicitly blacklisted by automated security scanners (URL:Blacklist).- [REMOTE_CODE_EXECUTION]: Automated security scanners have flagged the main skill file (SKILL.md) as having a malicious reputation (FileRepMalware), indicating a severe security risk.- [COMMAND_EXECUTION]: The skill instructs the agent to execute shell commands, including 'python manage.py migrate' and 'curl'. These tools provide a powerful interface for system interaction that can be exploited when paired with the malicious artifacts identified by scanners.- [INDIRECT_PROMPT_INJECTION]: The skill possesses an inherent attack surface by ingesting user-provided application requirements to drive its code generation and command execution workflows. It lacks explicit boundary markers or sanitization logic to protect against adversarial instructions embedded in the requirements. Evidence: Ingestion points in requirement analysis workflow; Boundary markers are absent; Capability inventory includes subprocess calls via manage.py and curl; Sanitization logic is absent.- [DATA_EXFILTRATION]: The combination of shell command execution capabilities and the presence of a blacklisted external domain presents a credible risk of sensitive information exfiltration from the development environment.
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
  • AI detected serious security threats
  • Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 5, 2026, 11:38 AM
Security Audit — agent-trust-hub — django-expert