CtrlK
BlogDocsLog inGet started
Tessl Logo

django-security

Django security best practices, authentication, authorization, CSRF protection, SQL injection prevention, XSS prevention, and secure deployment configurations. Use when reviewing Django authentication, authorization, input handling, or deployment settings.

60

Quality

72%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/django-security/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

57%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

The body delivers genuinely actionable, code-heavy Django security guidance and is well sectioned, but it is monolithic: duplicated header/CSP content, two competing file-validation implementations, and no progressive disclosure into reference files. It reads as a reference dump rather than an overview with a navigable structure, and it lacks a sequenced review workflow.

Suggestions

Consolidate the three overlapping sections on security headers and CSP (production settings, 'HTTP Headers', and 'Security Headers') into one canonical block to remove duplication.

Split topical deep-dives (file upload security, API security, RBAC) into reference files under references/ and keep SKILL.md as a lean overview with one-level-deep, clearly signaled links.

Add a sequenced workflow — e.g., an ordered security-review procedure that walks the Quick Security Checklist with validation checkpoints — instead of presenting purely parallel topic sections.

DimensionReasoningScore

Conciseness

The body is mostly code with little prose padding, but it contains notable duplication — security headers/CSP settings appear in three separate sections and there are two parallel file-validation implementations — plus restatements of Django defaults Claude already knows. It fits 'mostly efficient but includes some unnecessary content that could be tightened' more than the severely padded 2 anchor.

3 / 5

Actionability

Concrete, mostly copy-paste-ready code throughout (production settings, custom user model, validators, DRF permissions, throttling), with minor gaps: fragments use undefined names ('ImproperlyConfigured' and 'Response' without imports, 'User' referenced before it is defined), keeping it below the fully-executable 5 anchor.

4 / 5

Workflow Clarity

The body is a well-organized topical reference with a 'When to Activate' list and a closing checklist, but it presents no sequenced workflow (e.g., an ordered security-review or deployment-hardening procedure) and no validation checkpoints, matching the 'structure present but sequence/checkpoints missing' level rather than 4.

3 / 5

Progressive Disclosure

Section headers are clear and consistent, but ~640 lines of reference material are entirely inlined in SKILL.md with no references to separate files — content that clearly belongs in reference files (API security, file upload security, RBAC) is inline. This sits between the minimal-structure 2 anchor and the well-split 4 anchor.

3 / 5

Total

13

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong description: it clearly scopes the skill to Django security, names concrete capability areas, and includes an explicit 'Use when' trigger clause with natural phrasing. The only weakness is topic-noun phrasing rather than concrete actions and a few missing natural synonyms like 'permissions' or 'hardening'.

DimensionReasoningScore

Specificity

The description lists several concrete capability areas — 'authentication, authorization, CSRF protection, SQL injection prevention, XSS prevention, and secure deployment configurations' — giving minor gaps rather than the fully comprehensive, action-verb coverage of the 5 anchor.

4 / 5

Completeness

It explicitly answers both what ('Django security best practices, authentication, authorization, CSRF protection...') and when ('Use when reviewing Django authentication, authorization, input handling, or deployment settings') with concrete trigger phrases, matching the 5 anchor exactly.

5 / 5

Trigger Term Quality

Natural terms like 'Django', 'authentication', 'CSRF', 'SQL injection', and 'deployment settings' are present, but common variations such as 'permissions', 'security review', or 'hardening' are missing, matching the 'good coverage, a few natural terms missing' anchor.

4 / 5

Distinctiveness Conflict Risk

The description is tightly scoped to Django with named vulnerability classes, giving it a clear niche and minimal conflict risk beyond a hypothetical generic security-review skill.

5 / 5

Total

18

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

skill_md_line_count

SKILL.md is long (645 lines); consider splitting into references/ and linking

Warning

metadata_version

'metadata.version' is missing

Warning

Total

14

/

16

Passed

Repository
affaan-m/ECC
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.