CtrlK
BlogDocsLog inGet started
Tessl Logo

django-security

Django security best practices, authentication, authorization, CSRF protection, SQL injection prevention, XSS prevention, and secure deployment configurations.

56

Quality

64%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./docs/ja-JP/skills/django-security/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

63%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A dense, largely executable Django security reference with strong code examples and a useful closing checklist, organized into clear topical sections. Its weaknesses are monolithic structure (no reference files despite ~590 lines), duplicated blocks that waste tokens, and a few non-executable or internally contradictory snippets (CSRF HttpOnly vs. the JS cookie reader). Splitting topics into references/ and adding a deploy-check verification step would raise both structure scores.

Suggestions

Split the body into references/ files (e.g., references/api-security.md, references/file-uploads.md, references/deployment.md) and keep SKILL.md as a concise overview with well-signaled links plus the quick checklist.

Remove duplicated blocks: define the custom User model once, merge the two security-header/CSP middleware sections, and consolidate the two REST_FRAMEWORK dicts.

Add an explicit validation step such as `python manage.py check --deploy`, and fix the CSRF_COOKIE_HTTPONLY = True setting that contradicts the JavaScript getCookie('csrftoken') example.

DimensionReasoningScore

Conciseness

Prose is minimal and the body is mostly code, but there is noticeable duplication that could be trimmed: the custom User model is defined twice (認証 and RBAC sections), security headers and CSP middleware appear in two sections, and there are two separate REST_FRAMEWORK dicts plus repeated ALLOWED_HOSTS/SECRET_KEY settings. This fits 'mostly efficient but includes some unnecessary content or could be tightened' rather than the fully lean 4-5 band.

3 / 5

Actionability

Most guidance is concrete, executable settings and code (production settings, password validators, DRF permissions, file validators, GOOD/BAD SQL examples), matching 'mostly executable with minor gaps'. It is not 5 because several blocks are not copy-paste ready: the CSP middleware references undefined CSP_* constants, ImproperlyConfigured is raised without being imported, and CSRF_COOKIE_HTTPONLY = True contradicts the JavaScript getCookie('csrftoken') example that depends on reading that cookie.

4 / 5

Workflow Clarity

As a reference-style skill it is well organized: an explicit 'いつ有効化するか' activation list, clearly sequenced topic sections, and a final quick-check checklist that acts as a verification artifact, matching 'clear sequence with most checkpoints present; minor validation gaps'. It is not 5 because no executable verification step (e.g., python manage.py check --deploy) or feedback loop for fixing flagged issues is provided.

4 / 5

Progressive Disclosure

The single-file body has clear section headers but is ~590 lines, with substantial per-topic content (API security, file uploads, logging, CSP) inlined that would fit naturally in references/ files; no bundle files exist at all. This fits 'some structure but content that should be separate is inline' rather than 2, since headers make navigation possible.

3 / 5

Total

14

/

20

Passed

Description

66%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A domain-specific description that clearly states what the skill covers through six named security areas, with good natural trigger terms like CSRF, XSS, and SQL injection. Its main weakness is the complete absence of a 'Use when...' clause, which caps completeness and weakens trigger guidance. Adding explicit activation conditions and action-oriented verbs would lift it to the top band.

Suggestions

Append an explicit trigger clause, e.g., 'Use when configuring Django authentication or permissions, reviewing a Django app for security issues, hardening production settings, or deploying a Django project.'

Convert topic nouns into concrete actions ('Configure authentication and custom user models', 'Prevent SQL injection and XSS') to sharpen specificity.

Mention the additional covered areas from the body (file upload validation, API rate limiting, secrets/environment variables, security logging) so the description's coverage matches the content.

DimensionReasoningScore

Specificity

The description names the domain ('Django security best practices') and enumerates six concrete security areas ('authentication, authorization, CSRF protection, SQL injection prevention, XSS prevention, and secure deployment configurations'), matching the 'several specific actions; minor gaps' anchor. It falls short of 5 because these are topic nouns rather than concrete actions and coverage is incomplete relative to the body (file uploads, rate limiting, secrets management, logging are all missing).

4 / 5

Completeness

The 'what' is clear (Django security practices across the listed areas), but there is no 'Use when...' clause or equivalent trigger guidance anywhere in the description, capping completeness at 3 per the judging guidelines. It is not 2 because the 'what' is specific and multi-faceted rather than vague.

3 / 5

Trigger Term Quality

Natural phrases users would say are present ('Django', 'security', 'CSRF', 'XSS', 'authentication', 'secure deployment'), giving good keyword coverage. A few common natural terms are missing (e.g., 'hardening', 'permissions', 'OWASP', 'secrets'), so it does not reach the comprehensive-synonym coverage of 5.

4 / 5

Distinctiveness Conflict Risk

The description is firmly scoped to Django and its named protection areas, so it would rarely trigger for unrelated skills, fitting 'mostly distinct; minor overlap risk'. It is not 5 because 'security best practices' as a category overlaps somewhat with generic secure-coding or security-review skills.

4 / 5

Total

15

/

20

Passed

Validation

93%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 15 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

skill_md_line_count

SKILL.md is long (593 lines); consider splitting into references/ and linking

Warning

Total

15

/

16

Passed

Repository
affaan-m/ECC
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.