CtrlK
BlogDocsLog inGet started
Tessl Logo

django-security

Django security best practices, authentication, authorization, CSRF protection, SQL injection prevention, XSS prevention, and secure deployment configurations.

55

Quality

63%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./.kiro/skills/django-security/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

57%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A code-dense, genuinely actionable reference whose main weaknesses are redundancy (duplicated settings, User models, and REST_FRAMEWORK blocks), the absence of any sequenced review/hardening workflow, and no progressive disclosure — everything lives inline in one long file. Executable quality is good but a few examples have correctness gaps.

Suggestions

Deduplicate: merge the three security-header blocks and the two User-model definitions, and consolidate the two REST_FRAMEWORK dicts into one settings block.

Add a numbered workflow for the stated use cases (e.g. security review: check settings -> auth -> permissions -> upload handling -> headers -> logging), with a validation step such as running checks/deployment tests before shipping.

Split detailed per-topic material (auth, CSRF, file upload, API security) into references/ files and keep SKILL.md as an overview with clearly signaled links, per progressive disclosure.

DimensionReasoningScore

Conciseness

The body is mostly compact code with little padded prose, but it is noticeably redundant: security headers/settings appear in three places ('Core Security Settings', 'HTTP Headers', and the checklist), 'class User(AbstractUser)' is defined twice (Authentication and RBAC sections), and 'REST_FRAMEWORK' is defined in two separate blocks. Much of it also restates standard Django/DRF knowledge Claude already has (default password validators, DRF's canonical IsOwnerOrReadOnly). This fits 'mostly efficient but includes some unnecessary content that could be tightened' — not a 2 since it avoids explanatory filler, not a 4 given the multiple duplicated sections.

3 / 5

Actionability

Guidance is concrete and largely copy-paste ready: full settings blocks, working validators, middleware, and template patterns covering the common cases. Minor gaps keep it from a 5: the settings example raises ImproperlyConfigured without importing it, BurstRateThrottle/SustainedRateThrottle reference 'burst'/'sustained' scopes that are absent from DEFAULT_THROTTLE_RATES, two conflicting User models are shown, SECURE_BROWSER_XSS_FILTER is deprecated, and the format_html example double-escapes by passing escape(username) into format_html.

4 / 5

Workflow Clarity

The body is organized by topic with a 'When to Activate' list and a closing checklist, but there is no sequenced process for its stated use cases (e.g. 'Reviewing Django application for security issues' or 'Deploying Django applications to production') and no validation/verification checkpoints. That matches 'steps/structure present but checkpoints missing' rather than a 4, which requires a clear sequence with most checkpoints present.

3 / 5

Progressive Disclosure

Section headers provide reasonable structure, but ~590 lines are entirely inline with no bundle files at all; detailed reference material (authentication internals, CSRF details, file upload, API security) clearly belongs in separate reference files. This fits the anchor 'some structure but content that should be separate is inline' — not a 2 because navigation via headers is decent, not a 4 because nothing is split out.

3 / 5

Total

13

/

20

Passed

Description

70%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A solid, specific description with good trigger terminology and a clear Django-security niche. Its main weakness is the missing 'Use when...' trigger clause, which caps completeness and weakens discovery relative to the strongest examples.

Suggestions

Append an explicit trigger clause, e.g. 'Use when securing a Django app, reviewing a Django codebase for vulnerabilities, or configuring production security settings.'

Add natural-language variations users actually say ('secure my Django app', 'Django hardening', 'permissions') to broaden trigger matching.

DimensionReasoningScore

Specificity

The description enumerates several concrete capability areas — 'authentication, authorization, CSRF protection, SQL injection prevention, XSS prevention, and secure deployment configurations' — going beyond a bare domain claim. It falls short of a 5 because these are topic nouns rather than actions and coverage omits areas the body actually covers (file uploads, rate limiting, secrets management).

4 / 5

Completeness

The 'what' is clear (a list of security practice areas), but there is no 'Use when...' clause or equivalent trigger guidance anywhere in the description, which caps this dimension at 3 per the judging guidelines. It is not a 2 because the 'what' is concrete, and not a 4 because 'when' is entirely absent rather than just imprecise.

3 / 5

Trigger Term Quality

Natural user phrasings like 'Django', 'CSRF', 'SQL injection', 'XSS', and 'authentication' are present and would match real requests. A few common variations ('secure my Django app', 'harden', 'permissions') are missing, so it sits at the good-but-not-comprehensive anchor.

4 / 5

Distinctiveness Conflict Risk

'Django security' carves out a clear niche with distinct, specific triggers (CSRF, SQL injection, XSS in a Django context); minimal risk of firing for unrelated skills. The technology-specific framing keeps it well away from generic overlap.

5 / 5

Total

16

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

skill_md_line_count

SKILL.md is long (594 lines); consider splitting into references/ and linking

Warning

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

14

/

16

Passed

Repository
affaan-m/ECC
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.