CtrlK
BlogDocsLog inGet started
Tessl Logo

django-security

Django 安全最佳实践、认证、授权、CSRF 防护、SQL 注入预防、XSS 预防和安全部署配置。

80

1.17x
Quality

58%

Does it follow best practices?

Impact

95%

1.17x

Average score across 6 eval scenarios

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./docs/zh-CN/skills/django-security/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

50%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A highly actionable, well-sectioned Django security reference with strong GOOD/BAD code contrasts, but it is a monolithic ~590-line single file that largely restates Django knowledge Claude already has, with notable duplication across sections and no external reference files or sequenced review workflow. It would benefit substantially from splitting into reference files and trimming boilerplate.

Suggestions

Split into reference files (e.g., references/settings.md, references/api-security.md, references/file-uploads.md) and keep SKILL.md as a lean overview with a pointer to each, rather than inlining ~590 lines.

Remove the duplicated material — security headers appear in three sections (核心安全设置, HTTP 头部, 安全头部) and SECRET_KEY handling is shown twice — and delete boilerplate Django settings Claude already knows, keeping only project-specific decisions and the GOOD/BAD contrasts.

For the stated security-review use case, add a short sequenced workflow (e.g., 1. check DEBUG/ALLOWED_HOSTS/SECRET_KEY, 2. review auth/permission code, 3. audit raw SQL and mark_safe usage, 4. verify headers/CSP via the checklist) so the topical content becomes an actionable review process.

DimensionReasoningScore

Conciseness

At ~590 lines the body re-teaches standard Django security knowledge Claude already knows (SECURE_SSL_REDIRECT/HSTS/cookie flags, ORM parameter escaping, DRF permission classes) and duplicates content across sections — security headers appear in "核心安全设置" and again in "HTTP 头部" and "安全头部", SECRET_KEY handling is covered twice with two different code approaches, CSRF cookie settings repeat. This matches the anchor 'noticeably verbose; several unnecessary explanations or padded sections' rather than anchor 3's 'mostly efficient with some trimming needed'.

2 / 5

Actionability

The content is dominated by concrete, near copy-paste-ready code — production settings, custom user model, DRF permissions and throttles, validators, middleware, logging config — plus good GOOD/BAD contrasts for SQL injection (parameterized raw() vs f-string) and XSS (mark_safe vs format_html). It falls short of anchor 5 because several snippets have undefined names (ImproperlyConfigured never imported, Response used without import in protected_view, User referenced in Post and permissions snippets without definition), so they are not fully executable as written.

4 / 5

Workflow Clarity

The body is organized topically rather than as a workflow: there is a useful "何时启用" trigger list and a final security checklist, but no sequenced process (e.g., audit settings → fix → verify) and no validation checkpoints despite the skill explicitly targeting '审查 Django 应用程序的安全问题' (reviewing security issues), where a review-then-verify flow matters. This matches anchor 3: structure present, checkpoints missing or implicit.

3 / 5

Progressive Disclosure

The single SKILL.md is well-sectioned with clear ## headers (no wall-of-text problem), but it is ~590 lines of reference material inlined with zero bundle files — no references/, scripts/, or assets/ exist. Per the guideline, the under-50-lines exception does not apply, and content that clearly belongs in separate files (full settings catalogs, DRF/API security, CSP middleware details, logging config) is inlined. This matches anchor 3: 'some structure but could be better organized; content that should be separate is inline', stopping short of anchor 2 because section structure and navigation within the file are genuinely good.

3 / 5

Total

12

/

20

Passed

Description

66%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A specific, well-scoped Django security description with strong concrete keywords, but it omits any explicit 'use when' trigger guidance, which both caps completeness and weakens its value for skill triggering. Coverage also undersells the body's full scope (file uploads, API security, CSP, logging).

Suggestions

Append an explicit trigger clause, e.g. "Use when securing, auditing, or deploying a Django application, or when the user mentions CSRF, SQL injection, XSS, authentication, or hardening a Django site."

Add natural synonyms users actually say ("漏洞/vulnerabilities", "生产环境/production hardening", "渗透测试") to broaden trigger matching.

Mention the body's additional coverage areas (file upload security, API rate limiting, CSP/security headers, security logging) so the description accurately signals scope.

DimensionReasoningScore

Specificity

The description lists several concrete capability areas — "认证、授权、CSRF 防护、SQL 注入预防、XSS 预防和安全部署配置" (authentication, authorization, CSRF protection, SQL injection prevention, XSS prevention, secure deployment configuration) — which is well beyond vague domain-naming. It stops short of anchor 5 because coverage of the body's actual scope is incomplete: file upload security, API/rate limiting, security headers/CSP, and logging are all covered in the body but absent from the description.

4 / 5

Completeness

The 'what' is clear and specific (Django security best practices across six named areas), but the 'when' is entirely absent — there is no "Use when..." clause or equivalent explicit trigger guidance anywhere in the description. Per the judging guideline this caps completeness at 3, matching the anchor 'Has a clear what but when is missing or only weakly implied' (the body's "何时启用" section does not carry over into the description).

3 / 5

Trigger Term Quality

Good natural keyword coverage — users would say "Django 安全" (security), "CSRF", "SQL 注入", "XSS", "认证", "部署" — matching the anchor-4 example of good coverage with a few terms missing. It falls short of anchor 5 because common user phrasings like "漏洞" (vulnerabilities), "渗透测试" (pentesting), "加固" (hardening), or "生产环境" (production environment) are absent, and there are no file/tech extension-style synonyms.

4 / 5

Distinctiveness Conflict Risk

The description carves a clear niche — Django-specific security with distinct trigger terms (CSRF, SQL injection, XSS) unlikely to pull in unrelated skills. It sits at anchor 4 rather than 5 because "安全最佳实践" and "安全部署配置" (secure deployment configuration) leave moderate overlap risk with adjacent skills like a generic Django deployment/production-config or web-security skill.

4 / 5

Total

15

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

skill_md_line_count

SKILL.md is long (594 lines); consider splitting into references/ and linking

Warning

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

14

/

16

Passed

Repository
affaan-m/ECC
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.