Agent skill

Django Verification Loop

by affaan-m in affaan-m/ECC

Runs a phased pre-PR and pre-deploy check on a Django project: environment, linting, migrations, tests with coverage, security scans and settings review.

MITAuto-check passedDevelopment

Install Django Verification Loop

skills CLI
$ npx skills add affaan-m/ECC --skill django-verification -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install affaan-m/ECC django-verification --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/affaan-m/ECC.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/django-verification .claude/skills/django-verification && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
django-verification
GitHub stars
277k
Used in
7 other repos
Token cost
~2.9k tokens
SKILL.md length
378 words
Files
1
Skills in repo
683
Repo updated
First seen
Licence
MIT

At a glance

Runs a phased pre-PR and pre-deploy check on a Django project: environment, linting, migrations, tests with coverage, security scans and settings review.

  • Works in 12 steps: Environment Check → Code Quality & Formatting → Migrations → …
  • Before opening a pull request on a Django project
  • SKILL.md covers When to Activate, Phase 1: Environment Check, Phase 2: Code Quality &… and Phase 3: Migrations, plus 13 more sections
  • Calls python, git and pytest; needs SECRET_KEY and DJANGO_SECRET_KEY

What it does

This skill runs a multi-phase verification pass on a Django application before a pull request, after major model or dependency changes, and ahead of staging or production deploys. The phases cover the environment, code quality and formatting with mypy, ruff and black, migrations, tests with coverage, security scans, Django management commands, performance checks and static assets, ending in a pass or fail report.

Migration checks report pending migrations, conflicts and model changes without migrations. Tests run through pytest with coverage targets of 90% for models and services, 85% for serializers, 80% for views and 80% overall. Security checks use pip-audit, safety and bandit and look for vulnerable dependencies, hardcoded secrets and DEBUG left on in production. Performance checks hunt for N+1 and duplicate queries and missing indexes, with fewer than 50 queries per typical page as the guide, and npm audit covers static asset dependencies.

When your agent uses it

  • Before opening a pull request on a Django project
  • After model changes, migration updates or dependency upgrades
  • Running pre-deploy readiness checks for staging or production
  • Validating migration safety and test coverage targets

Example prompts

  • “Run the full Django verification loop on this branch and give me a pass/fail report.”
  • “We changed several models; check the migrations and make sure coverage still meets the targets.”
  • “Scan our Django dependencies and settings for security problems before tonight's deploy.”

Requirements

  • A Django project with pytest and coverage configured
  • mypy, ruff, black, pip-audit and bandit installed

Workflow steps

12 steps, taken from the step headings in SKILL.md.

  1. Environment Check
  2. Code Quality & Formatting
  3. Migrations
  4. Tests + Coverage
  5. Security Scan
  6. Django Management Commands
  7. Performance Checks
  8. Static Assets
  9. Configuration Review
  10. Logging Configuration
  11. API Documentation (if DRF)
  12. Diff Review

What it can do on your machine

Read from SKILL.md and the folder at commit 2d515e4. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • python
    • git
    • pytest
    • black
    • npm
    • mypy
    • ruff
    • pip
    • gitleaks
    • django-admin

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, npm and pip, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • SECRET_KEY
    • DJANGO_SECRET_KEY
    • POSTGRES_PASSWORD

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Django Verification Loop loads about 2.9k tokens when it runs. Until then it costs about 103 tokens; SKILL.md has 378 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~103
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from affaan-m/ECC at commit 2d515e4, republished under its MIT licence (© affaan-m). 378 words, ~2,910 tokens.

Download SKILL.mdSave it as .claude/skills/django-verification/SKILL.md (or your agent's skills folder).
name
django-verification
description
Run the full Django verification loop — environment check, mypy/ruff/black linting, migration safety, pytest with coverage targets, pip-audit and bandit security scans, settings and logging review, and diff review — producing a phased pass/fail report before release or PR. Use when preparing a Django pull request, validating migrations or coverage, or running pre-deploy readiness checks.
metadata.origin
ECC

Django Verification Loop

Run before PRs, after major changes, and pre-deploy to ensure Django application quality and security.

When to Activate

  • Before opening a pull request for a Django project
  • After major model changes, migration updates, or dependency upgrades
  • Pre-deployment verification for staging or production
  • Running full environment → lint → test → security → deploy readiness pipeline
  • Validating migration safety and test coverage

Phase 1: Environment Check

bash
# Verify Python version
python --version  # Should match project requirements

# Check virtual environment
which python
pip list --outdated

# Verify environment variables
python -c "import os; import environ; print('DJANGO_SECRET_KEY set' if os.environ.get('DJANGO_SECRET_KEY') else 'MISSING: DJANGO_SECRET_KEY')"

If environment is misconfigured, stop and fix.

Phase 2: Code Quality & Formatting

bash
# Type checking
mypy . --config-file pyproject.toml

# Linting with ruff
ruff check . --fix

# Formatting with black
black . --check
black .  # Auto-fix

# Import sorting
isort . --check-only
isort .  # Auto-fix

# Django-specific checks
python manage.py check --deploy

Common issues:

  • Missing type hints on public functions
  • PEP 8 formatting violations
  • Unsorted imports
  • Debug settings left in production configuration

Phase 3: Migrations

bash
# Check for unapplied migrations
python manage.py showmigrations

# Create missing migrations
python manage.py makemigrations --check

# Dry-run migration application
python manage.py migrate --plan

# Apply migrations (test environment)
python manage.py migrate

# Check for migration conflicts
python manage.py makemigrations --merge  # Only if conflicts exist

Report:

  • Number of pending migrations
  • Any migration conflicts
  • Model changes without migrations

Phase 4: Tests + Coverage

bash
# Run all tests with pytest
pytest --cov=apps --cov-report=html --cov-report=term-missing --reuse-db

# Run specific app tests
pytest apps/users/tests/

# Run with markers
pytest -m "not slow"  # Skip slow tests
pytest -m integration  # Only integration tests

# Coverage report
open htmlcov/index.html

Report:

  • Total tests: X passed, Y failed, Z skipped
  • Overall coverage: XX%
  • Per-app coverage breakdown

Coverage targets:

ComponentTarget
Models90%+
Serializers85%+
Views80%+
Services90%+
Overall80%+

Phase 5: Security Scan

bash
# Dependency vulnerabilities
pip-audit
safety check --full-report

# Django security checks
python manage.py check --deploy

# Bandit security linter
bandit -r . -f json -o bandit-report.json

# Secret scanning (if gitleaks is installed)
gitleaks detect --source . --verbose

# Environment variable check
python -c "from django.core.exceptions import ImproperlyConfigured; from django.conf import settings; settings.DEBUG"

Report:

  • Vulnerable dependencies found
  • Security configuration issues
  • Hardcoded secrets detected
  • DEBUG mode status (should be False in production)

Phase 6: Django Management Commands

bash
# Check for model issues
python manage.py check

# Collect static files
python manage.py collectstatic --noinput --clear

# Create superuser (if needed for tests)
echo "from apps.users.models import User; User.objects.create_superuser('admin@example.com', 'admin')" | python manage.py shell

# Database integrity
python manage.py check --database default

# Cache verification (if using Redis)
python -c "from django.core.cache import cache; cache.set('test', 'value', 10); print(cache.get('test'))"

Phase 7: Performance Checks

bash
# Django Debug Toolbar output (check for N+1 queries)
# Run in dev mode with DEBUG=True and access a page
# Look for duplicate queries in SQL panel

# Query count analysis
django-admin debugsqlshell  # If django-debug-sqlshell installed

# Check for missing indexes
python manage.py shell << EOF
from django.db import connection
with connection.cursor() as cursor:
    cursor.execute("SELECT table_name, index_name FROM information_schema.statistics WHERE table_schema = 'public'")
    print(cursor.fetchall())
EOF

Report:

  • Number of queries per page (should be < 50 for typical pages)
  • Missing database indexes
  • Duplicate queries detected

Phase 8: Static Assets

bash
# Check for npm dependencies (if using npm)
npm audit
npm audit fix

# Build static files (if using webpack/vite)
npm run build

# Verify static files
ls -la staticfiles/
python manage.py findstatic css/style.css

Phase 9: Configuration Review

python
# Run in Python shell to verify settings
python manage.py shell << EOF
from django.conf import settings
import os

# Critical checks
checks = {
    'DEBUG is False': not settings.DEBUG,
    'SECRET_KEY set': bool(settings.SECRET_KEY and len(settings.SECRET_KEY) > 30),
    'ALLOWED_HOSTS set': len(settings.ALLOWED_HOSTS) > 0,
    'HTTPS enabled': getattr(settings, 'SECURE_SSL_REDIRECT', False),
    'HSTS enabled': getattr(settings, 'SECURE_HSTS_SECONDS', 0) > 0,
    'Database configured': settings.DATABASES['default']['ENGINE'] != 'django.db.backends.sqlite3',
}

for check, result in checks.items():
    status = '✓' if result else '✗'
    print(f"{status} {check}")
EOF

Phase 10: Logging Configuration

bash
# Test logging output
python manage.py shell << EOF
import logging
logger = logging.getLogger('django')
logger.warning('Test warning message')
logger.error('Test error message')
EOF

# Check log files (if configured)
tail -f /var/log/django/django.log

Phase 11: API Documentation (if DRF)

bash
# Generate schema
python manage.py generateschema --format openapi-json > schema.json

# Validate schema
# Check if schema.json is valid JSON
python -c "import json; json.load(open('schema.json'))"

# Access Swagger UI (if using drf-yasg)
# Visit http://localhost:8000/swagger/ in browser
Show full SKILL.md (167 more words)Show less

Phase 12: Diff Review

bash
# Show diff statistics
git diff --stat

# Show actual changes
git diff

# Show changed files
git diff --name-only

# Check for common issues
git diff | grep -i "todo\|fixme\|hack\|xxx"
git diff | grep "print("  # Debug statements
git diff | grep "DEBUG = True"  # Debug mode
git diff | grep "import pdb"  # Debugger

Checklist:

  • No debugging statements (print, pdb, breakpoint())
  • No TODO/FIXME comments in critical code
  • No hardcoded secrets or credentials
  • Database migrations included for model changes
  • Configuration changes documented
  • Error handling present for external calls
  • Transaction management where needed

Output Template

DJANGO VERIFICATION REPORT
==========================

Phase 1: Environment Check
  ✓ Python 3.11.5
  ✓ Virtual environment active
  ✓ All environment variables set

Phase 2: Code Quality
  ✓ mypy: No type errors
  ✗ ruff: 3 issues found (auto-fixed)
  ✓ black: No formatting issues
  ✓ isort: Imports properly sorted
  ✓ manage.py check: No issues

Phase 3: Migrations
  ✓ No unapplied migrations
  ✓ No migration conflicts
  ✓ All models have migrations

Phase 4: Tests + Coverage
  Tests: 247 passed, 0 failed, 5 skipped
  Coverage:
    Overall: 87%
    users: 92%
    products: 89%
    orders: 85%
    payments: 91%

Phase 5: Security Scan
  ✗ pip-audit: 2 vulnerabilities found (fix required)
  ✓ safety check: No issues
  ✓ bandit: No security issues
  ✓ No secrets detected
  ✓ DEBUG = False

Phase 6: Django Commands
  ✓ collectstatic completed
  ✓ Database integrity OK
  ✓ Cache backend reachable

Phase 7: Performance
  ✓ No N+1 queries detected
  ✓ Database indexes configured
  ✓ Query count acceptable

Phase 8: Static Assets
  ✓ npm audit: No vulnerabilities
  ✓ Assets built successfully
  ✓ Static files collected

Phase 9: Configuration
  ✓ DEBUG = False
  ✓ SECRET_KEY configured
  ✓ ALLOWED_HOSTS set
  ✓ HTTPS enabled
  ✓ HSTS enabled
  ✓ Database configured

Phase 10: Logging
  ✓ Logging configured
  ✓ Log files writable

Phase 11: API Documentation
  ✓ Schema generated
  ✓ Swagger UI accessible

Phase 12: Diff Review
  Files changed: 12
  +450, -120 lines
  ✓ No debug statements
  ✓ No hardcoded secrets
  ✓ Migrations included

RECOMMENDATION: WARNING: Fix pip-audit vulnerabilities before deploying

NEXT STEPS:
1. Update vulnerable dependencies
2. Re-run security scan
3. Deploy to staging for final testing

Pre-Deployment Checklist

  • All tests passing
  • Coverage ≥ 80%
  • No security vulnerabilities
  • No unapplied migrations
  • DEBUG = False in production settings
  • SECRET_KEY properly configured
  • ALLOWED_HOSTS set correctly
  • Database backups enabled
  • Static files collected and served
  • Logging configured and working
  • Error monitoring (Sentry, etc.) configured
  • CDN configured (if applicable)
  • Redis/cache backend configured
  • Celery workers running (if applicable)
  • HTTPS/SSL configured
  • Environment variables documented

Continuous Integration

GitHub Actions Example
yaml
# .github/workflows/django-verification.yml
name: Django Verification

on: [push, pull_request]

jobs:
  verify:
    runs-on: ubuntu-latest
    services:
      postgres:
        image: postgres:14
        env:
          POSTGRES_PASSWORD: postgres
        options: >-
          --health-cmd pg_isready
          --health-interval 10s
          --health-timeout 5s
          --health-retries 5

    steps:
      - uses: actions/checkout@v3

      - name: Set up Python
        uses: actions/setup-python@v4
        with:
          python-version: '3.11'

      - name: Cache pip
        uses: actions/cache@v3
        with:
          path: ~/.cache/pip
          key: ${{ runner.os }}-pip-${{ hashFiles('**/requirements.txt') }}

      - name: Install dependencies
        run: |
          pip install -r requirements.txt
          pip install ruff black mypy pytest pytest-django pytest-cov bandit safety pip-audit

      - name: Code quality checks
        run: |
          ruff check .
          black . --check
          isort . --check-only
          mypy .

      - name: Security scan
        run: |
          bandit -r . -f json -o bandit-report.json
          safety check --full-report
          pip-audit

      - name: Run tests
        env:
          DATABASE_URL: postgres://postgres:postgres@localhost:5432/test
          DJANGO_SECRET_KEY: test-secret-key
        run: |
          pytest --cov=apps --cov-report=xml --cov-report=term-missing

      - name: Upload coverage
        uses: codecov/codecov-action@v3

Quick Reference

CheckCommand
Environmentpython --version
Type checkingmypy .
Lintingruff check .
Formattingblack . --check
Migrationspython manage.py makemigrations --check
Testspytest --cov=apps
Securitypip-audit && bandit -r .
Django checkpython manage.py check --deploy
Collectstaticpython manage.py collectstatic --noinput
Diff statsgit diff --stat

Remember: Automated verification catches common issues but doesn't replace manual code review and testing in staging environment.

© affaan-m, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/django-verification of affaan-m/ECC.

Open the folder on GitHubat commit 2d515e4

Used in 7 other repositories

We found 15 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 7 other GitHub owners. This page covers the copy in affaan-m/ECC, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Django Verification Loop next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Django Verification Loop compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Django Verification Loop this skillaffaan-m/ECC277k7 repos~2.9kAutomated safety check: PassMIT
PR Preflight Checkliaohch3/claude-tap3.3k—~615Automated safety check: PassMIT
Python Idiomsirahardianto/awesome-agv156—~4.4kAutomated safety check: PassMIT
Checkav1155/houndarr292—~366Automated safety check: PassAGPL-3.0
Run And Verifyaropan/clist439—~461Automated safety check: PassApache-2.0
Validatejuliepy/AI-Engineer-from-scrach441—~500Automated safety check: PassNone

Similar skills

  • PR Preflight Check

    liaohch3/claude-tap

    Runs a single merge-readiness check on a pull request: metadata, GitHub Actions status, local lint, format and test gates, and PR body rules, ending in READY or NOT_READY.

    3.3k GitHub stars~615 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Python Idioms

    irahardianto/awesome-agv

    Modern Python (3.11+) idioms: type annotations, typing Protocols, Pydantic models, asyncio, pytest fixtures, and Ruff/Mypy strict compliance.

    156 GitHub stars~4.4k tokensUpdated 6 days ago
    DevelopmentAuto-check passed
  • Check

    av1155/houndarr

    Run Houndarr's full quality gate (ruff lint, ruff format check, mypy, bandit, pytest) and report results in a single table.

    292 GitHub stars~366 tokensUpdated 5 days ago
    Testing & QAAuto-check passed
  • Run And Verify

    aropan/clist

    Choose and run focused checks after changing CLIST Python code: Django tests, standalone pytest tests, offline parser fixtures, Ruff, or a relevant management-command check.

    439 GitHub stars~461 tokensUpdated 6 days ago
    Backend & APIsAuto-check passed
  • Validate

    juliepy/AI-Engineer-from-scrach

    Run the full quality gate (ruff + mypy + pytest + tsc + vitest) and report PASS/FAIL for each command.

    441 GitHub stars~500 tokensUpdated 1 mo ago
    Testing & QAAuto-check passed
  • Kedro Babysit

    kedro-org/kedro

    Run Kedro's local lint / format / type-check / tests on changed files (uses the project's pre-commit hooks, ruff, mypy, pytest, lint-imports, detect-secrets, Make targets — in the right venv), or…

    11k GitHub stars~4k tokensUpdated yesterday
    DevelopmentAuto-check passed

More from affaan-m/ECC

All 682 skills in this repo
  • Skill Stocktake

    affaan-m/ECC

    Audits your installed Claude skills and commands for quality, with a quick mode for recently changed skills and a full mode that evaluates all of them through subagents.

    277k GitHub starsUsed in 5 repos~3.1k tokens
    Auto-check passed
  • Ingests, indexes, searches, edits and monitors video, audio and live streams through the VideoDB Python SDK, returning stream links, clips and timestamps.

    277k GitHub starsUsed in 3 repos~3.5k tokens
    Auto-check: notes
  • Docs Governance

    affaan-m/ECC

    Route broad documentation-governance requests to existing ECC skills and run an opt-in, read-only audit of mapped documentation roles, links, ADR indexes, and evidence references.

    277k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Rules Distillation

    affaan-m/ECC

    Scans installed skills for principles that recur across them and proposes rule-file changes: append, revise, add a section, create a file or leave as covered.

    277k GitHub starsUsed in 2 repos~2.3k tokens
    Auto-check passed
  • Builds DRAFT counterparty agreements from one markdown template and a small JSON spec per party, with clauses picked by the party's role.

    277k GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Set an ECC-specific frontend design direction for production UI work.

    277k GitHub starsUsed in 1 repo~2.2k tokens
    Auto-check passed

Questions about Django Verification Loop

What does Django Verification Loop do?

Runs a phased pre-PR and pre-deploy check on a Django project: environment, linting, migrations, tests with coverage, security scans and settings review. This skill runs a multi-phase verification pass on a Django application before a pull request, after major model or dependency changes, and ahead of staging or production deploys. The phases cover the environment, code quality and formatting with mypy, ruff and black, migrations, tests with coverage, security scans, Django management commands, performance checks and static assets, ending in a pass or fail report.

When should I use Django Verification Loop?

Django Verification Loop fits situations like: before opening a pull request on a Django project; after model changes, migration updates or dependency upgrades; running pre-deploy readiness checks for staging or production; validating migration safety and test coverage targets.

How do I install Django Verification Loop in Claude Code?

Run `npx skills add affaan-m/ECC --skill django-verification -a claude-code`. Or copy the skill folder (skills/django-verification in affaan-m/ECC) into .claude/skills/django-verification in your project. Claude Code loads it when a task matches its description.

How do I install Django Verification Loop in Codex?

Run `npx skills add affaan-m/ECC --skill django-verification -a codex`. Or copy the skill folder (skills/django-verification in affaan-m/ECC) into .agents/skills/django-verification in your project. Codex loads it when a task matches its description.

Can I use Django Verification Loop in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add affaan-m/ECC --skill django-verification -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/django-verification, .gemini/skills/django-verification, .github/skills/django-verification and .opencode/skills/django-verification in your project.

What does Django Verification Loop need to run?

Going by SKILL.md and its folder, Django Verification Loop needs the command-line tools its instructions call (python, git, pytest, black, npm and mypy) and credentials named SECRET_KEY, DJANGO_SECRET_KEY and POSTGRES_PASSWORD. Our summary lists: A Django project with pytest and coverage configured; mypy, ruff, black, pip-audit and bandit installed.

Does Django Verification Loop access the network?

SKILL.md contains no URLs. Its commands use git, npm and pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Django Verification Loop safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Django Verification Loop use?

Django Verification Loop is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Django Verification Loop use?

About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Django Verification Loop?

Skills that share tags, products or a category with Django Verification Loop: PR Preflight Check (liaohch3/claude-tap, 3.3k stars), Python Idioms (irahardianto/awesome-agv, 156 stars), Check (av1155/houndarr, 292 stars) and Run And Verify (aropan/clist, 439 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Django Verification Loop?

affaan-m (a GitHub user) maintains it in affaan-m/ECC, which has 276,673 GitHub stars. The repository holds 683 skills in this directory. The repository was last updated on October 11, 2026.

Source: affaan-m/ECC on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.