dmr-from-drf

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze existing project code (DRF views, serializers, and test suites) to perform migrations. This creates an attack surface where maliciously crafted comments or code in the target repository could attempt to influence the agent's behavior during the refactoring process.
  • Ingestion points: Scans project API entrypoints, URL wiring, and test files (SKILL.md, Step 1 & 3).
  • Boundary markers: The instructions do not define specific delimiters for separating untrusted code from instructions.
  • Capability inventory: Includes the ability to write/modify local source code and execute repository-native CI/test entrypoints (SKILL.md, Step 11).
  • Sanitization: No explicit code sanitization or validation of the input source code is specified beyond standard linter checks.
  • [EXTERNAL_DOWNLOADS]: The skill references documentation from 'django-modern-rest.readthedocs.io' and 'django-rest-framework.org'. These are official framework documentation sites and represent well-known, trusted technical resources.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:01 PM
Security Audit — agent-trust-hub — dmr-from-drf