python2-to-3-django-upgrade-auditor

Pass

Audited by Gen Agent Trust Hub on Aug 3, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes a bash script (scripts/audit-python-django.sh) that performs read-only scans of project files to identify migration risks. The script implements security best practices, including path traversal validation (detecting /../) and restricting operations to the user-specified directory.
  • [EXTERNAL_DOWNLOADS]: While the skill instructions mention using pip for dependency management during migration, they explicitly prohibit silent installations and require user confirmation. It also explicitly forbids the dangerous curl | bash pattern.
  • [DATA_EXFILTRATION]: No network operations or external data transfer mechanisms were found. The skill contains explicit rules against printing secrets, credentials, or connection strings in logs or reports.
  • [SAFE]: The skill follows a structured 'Audit-Plan-Execute' workflow with clear security guardrails, such as prohibiting eval, requiring backups before destructive operations, and validating syntax after modifications.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 3, 2026, 04:50 AM