Django Unfold

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only Django Unfold helper; its main caveat is broad activation wording, not hidden or harmful behavior.

Safe to install as a Django Unfold reference skill. Before applying snippets, review any admin actions you copy, especially examples that update records, send email, or process refunds, and be aware the skill may activate for generic Django admin requests when django-unfold is present.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
92% confidence
Finding
The trigger guidance is explicitly broad enough to activate this skill for 'any Django admin feature' whenever django-unfold is present, even if the user did not ask about Unfold. That can cause inappropriate routing, overshadow more relevant skills, and lead the agent to provide mismatched framework-specific guidance that changes user outcomes or configuration advice unexpectedly.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal