django-api

Fail

Audited by Socket on Mar 10, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
SKILL.md

The skill content aligns well with its stated purpose of guiding Django API development and framework comparison. It uses official, well-known packages (e.g., django-ninja, DRF, httpx) accessed via standard channels (pip, settings). There are no credential exposures, no runnable download-execute chains, and no anomalous data sinks beyond legitimate API/database interactions and placeholder external calls. Overall, the footprint is benign with low security risk. Maintain attention to ensuring external calls in production target trusted services and avoid automatic execution of documentation snippets.

Confidence: 98%
Audit Metadata
Analyzed At
Mar 10, 2026, 06:50 AM
Package URL
pkg:socket/skills-sh/jpoutrin%2Fproduct-forge%2Fdjango-api%2F@04337dd479d5fb2d136a52758dbd13be17b034b0