Agent skill

Django

by ericrisco in ericrisco/rsc-harness

A skill your agent uses when building, reviewing, securing, testing or shipping a Django app — models, migrations, QuerySets/managers, FBV/CBV views, forms, the admin, settings split, and Django…

MITAuto-check passedBackend & APIs

Install Django

skills CLI
$ npx skills add ericrisco/rsc-harness --skill django -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ericrisco/rsc-harness django --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/django .claude/skills/django && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
django
GitHub stars
156
Token cost
~3.1k tokens
SKILL.md length
1,036 words
Files
8 (incl. scripts, references)
Skills in repo
229
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when building, reviewing, securing, testing or shipping a Django app — models, migrations, QuerySets/managers, FBV/CBV views, forms, the admin, settings split, and Django…

  • Shipping a Django app — models
  • SKILL.md covers Pinned stack (2026-06), Route elsewhere, Project shape and Models, plus 8 more sections
  • Runs Shell scripts from its folder; calls python; needs SECRET_KEY
  • QuerySets/managers

What it does

Django is an agent skill from ericrisco/rsc-harness. Use when building, reviewing, securing, testing or shipping a Django app — models, migrations, QuerySets/managers, FBV/CBV views, forms, the admin, settings split, and Django REST Framework (serializers, ModelViewSet, permissions). NOT async FastAPI/Pydantic services (that is fastapi), NOT Postgres schema/index work (that is postgresdb).

Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts and reference files (for example `evals/README.md`, `evals/cases.yaml` and `references/drf.md`).

It sits in Backend & APIs, covering Backend development. It works with Django, FastAPI, PostgreSQL and Pydantic. The repository describes itself as: Your agent invents things because it has no memory, and can't touch your database because it has no arms. rsc is the meta-harness that gives it both, plus the trade to know the… The licence is MIT.

When your agent uses it

  • Shipping a Django app — models
  • QuerySets/managers
  • Django REST Framework (serializers

Example prompts

  • “/django”

Requirements

  • Python 3
  • A Bash shell
  • A credential in SECRET_KEY

What it can do on your machine

Read from SKILL.md and the folder at commit 92fde8f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • SECRET_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Django loads about 3.1k tokens when it runs, and up to ~6.3k if it reads all its reference files. Until then it costs about 88 tokens; SKILL.md has 1,036 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~88
When it runs · the whole SKILL.md, loaded when a task matches
~3.1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from ericrisco/rsc-harness at commit 92fde8f, republished under its MIT licence (© ericrisco). 1,036 words, ~3,089 tokens.

Download SKILL.mdSave it as .claude/skills/django/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
django
description
Use when building, reviewing, securing, testing or shipping a Django app — models, migrations, QuerySets/managers, FBV/CBV views, forms, the admin, settings split, and Django REST Framework (serializers, ModelViewSet, permissions). NOT async FastAPI/Pydantic services (that is `fastapi`), NOT Postgres schema/index work (that is `postgresdb`).
tags
python, django, orm, drf, backend, web
recommends
postgresdb, secure-coding, deployment, testing-py, api-design
origin
risco

Django web applications

The single authoritative skill for building, reviewing, securing, testing and shipping a Django app — the batteries-included, ORM-first, request/response Python framework.

Mental model: a Django project is apps composed of fat-but-thin-enough models (domain + query logic on the model/manager), views that orchestrate (FBV/CBV/DRF) and never own SQL, an admin/forms layer, and a settings module split by environment. The ORM, migrations, auth, admin, CSP and the test runner are all first-party. Reach for the framework before you add a dependency.

Pinned stack (2026-06)

  • Django 5.2 LTS — the production default. Released 2025-04-02, security fixes until ~April 2028, supports Python 3.10–3.14. New in 5.2: all models auto-imported in shell, CompositePrimaryKey, BoundField customization.
  • Django 6.0 — released 2025-12-03 (non-LTS, ~8 months until 6.1). Choose it only when you want the new built-in Tasks framework (background jobs without Celery) or native CSP (ContentSecurityPolicyMiddleware, SECURE_CSP) and can take the shorter support window. Drops Python 3.10/3.11; supports 3.12–3.14.
  • Django REST Framework 3.17.1 (2026-03-24) — adds Django 6.0 + Python 3.14 support.
  • Python 3.12+, pytest-django, factory_boy. ruff/uv and type-hint policy live in python.

Version rule: default to 5.2 LTS. Pick 6.0 only for a concrete Tasks/CSP need, and say so.

Route elsewhere

SituationRoute to
Async service, fastapi/pydantic/uvicorn, async SQLAlchemyfastapi
Postgres schema design, EXPLAIN ANALYZE, indexing strategy, RLS, poolingpostgresdb
Cross-stack OWASP/STRIDE threat modelingsecure-coding
Container/Compose/CI, gunicorn prod tuning, collectstatic pipelinedeployment
REST contract design (cursor vs offset, status codes, versioning)api-design
ruff/uv/general type hints, packagingpython

Project shape

Split settings by environment; never ship one settings.py toggled by DEBUG.

text
src/
  manage.py
  config/
    settings/
      base.py      # shared; reads secrets from os.environ
      dev.py       # from base import *; DEBUG=True; local hosts
      prod.py      # from base import *; DEBUG=False; SECURE_*; CSP
  catalog/         # an app = a bounded domain
    models.py  managers.py  views.py  serializers.py  urls.py  admin.py
    migrations/
    tests/
  • Read secrets with os.environ["SECRET_KEY"] (or django-environ). Never commit a literal SECRET_KEY — a leaked key forges sessions and signed tokens.
  • Select env via DJANGO_SETTINGS_MODULE=config.settings.prod, not an if DEBUG branch.
  • One app = one domain. Resist a single core app that accretes everything.

Models

Put domain and query logic on the model and its manager. The view stays thin.

python
# managers.py
from django.db import models

class ArticleQuerySet(models.QuerySet):
    def published(self):
        return self.filter(status=Article.Status.PUBLISHED)

    def for_reader(self):  # composes; reused everywhere, tested once
        return self.published().select_related("author")

# models.py
class Article(models.Model):
    class Status(models.TextChoices):
        DRAFT = "draft", "Draft"
        PUBLISHED = "published", "Published"

    tenant = models.ForeignKey("Tenant", on_delete=models.CASCADE)
    slug = models.SlugField()
    author = models.ForeignKey("Author", on_delete=models.PROTECT)
    status = models.CharField(max_length=16, choices=Status.choices, default=Status.DRAFT)
    published_at = models.DateTimeField(null=True, blank=True)

    objects = ArticleQuerySet.as_manager()

    class Meta:
        constraints = [
            models.UniqueConstraint(fields=["tenant", "slug"], name="uniq_tenant_slug"),
            models.CheckConstraint(
                check=models.Q(status="draft") | models.Q(published_at__isnull=False),
                name="published_needs_date",
            ),
        ]
        indexes = [models.Index(fields=["tenant", "status"])]
  • Constraints live in the DB, not just Python. A UniqueConstraint/CheckConstraint is enforced under concurrency; a clean() check is not. Validate-in-Python-only is a foot-gun.
  • on_delete is mandatory and load-bearing: CASCADE deletes children, PROTECT blocks the delete, SET_NULL orphans. Choosing wrong silently destroys data — pick deliberately.
  • Multi-column PK (5.2+): pk = models.CompositePrimaryKey("tenant_id", "id").
  • Bad→Good for business logic:
python
# Bad: logic in the view — untested, unreusable, duplicated across endpoints
def publish(request, pk):
    a = Article.objects.get(pk=pk)
    a.status = "published"; a.published_at = timezone.now(); a.save()

# Good: a method on the model — one place, testable, reused by view/admin/command
class Article(models.Model):
    def publish(self):
        self.status = self.Status.PUBLISHED
        self.published_at = timezone.now()
        self.save(update_fields=["status", "published_at"])

QuerySet performance

The N+1 is the single most common Django defect: one query for the list, then one more per row.

python
# Bad: 1 + N queries — each .author touches the DB inside the loop
for a in Article.objects.all():
    print(a.author.name)

# Good: 2 queries total (FK -> JOIN; reverse/M2M -> second query)
for a in Article.objects.select_related("author").prefetch_related("tags"):
    print(a.author.name, [t.name for t in a.tags.all()])
You are followingUseCost
Forward ForeignKey / OneToOneselect_related(...)SQL JOIN, 1 query
Reverse FK, ManyToManyprefetch_related(...)2nd query, joined in Python
Prefetch that itself needs filter/orderPrefetch("x", queryset=...)controlled 2nd query
  • Need existence, not rows? qs.exists(), never len(qs) or if qs.count().
  • Need a few columns of a wide row? .only("id", "slug") / .defer("body").
  • Computed totals belong in the DB: annotate(...) / aggregate(...), not a Python loop.
  • Many inserts: bulk_create(objs) — one round-trip, not N .save() calls.
  • Never Model.objects.all() then slice/filter in Python; push it into the QuerySet.

Deeper recipes (assertNumQueries, Prefetch, .explain(), ORM indexing) → references/orm-performance.md.

Views & URLs

Keep views thin: validate input, call a model/manager method, return a response. No SQL.

NeedUse
One bespoke action, custom flowfunction-based view (FBV)
Standard list/detail/create/update/delete on a modelgeneric CBV (ListView, DetailView, …)
JSON API consumed by a client/SPAdrop to DRF (do not hand-roll JsonResponse CRUD)

For the DRF surface — serializers, ModelViewSet, routers, permissions, throttling, pagination, filtering, nested-serializer N+1, versioning — see references/drf.md. The thin-view rule still holds: a fat serializer that walks relations per row is just an N+1 wearing a tie.

Migrations

bash
python manage.py makemigrations catalog   # generate from model diff
python manage.py migrate                   # apply
python manage.py makemigrations --check    # CI gate: fail if a model drifts from migrations
  • Never edit a migration that has been applied anywhere. Add a new one. Editing rewrites history and breaks every environment that already ran it.
  • Data backfills go through migrations.RunPython(forward, reverse) with a reverse, not a one-off script. Use the historical model from apps.get_model(...), not the imported class.
  • Schema changes on a live table that you cannot afford to lock are expand-and-contract; the Postgres-side mechanics (lock modes, batching) live in postgresdb.
Show full SKILL.md (405 more words)Show less

Security

Set these in prod.py. Then prove it: python manage.py check --deploy must come back clean.

SettingValueWhy
DEBUGFalseTrue leaks settings + a stack-trace shell to the world
ALLOWED_HOSTSexplicit domains['*'] enables Host-header attacks
SECRET_KEYfrom os.environa literal in source forges signed cookies/tokens
SECURE_SSL_REDIRECTTrueforce HTTPS
SECURE_HSTS_SECONDS31536000 (+ include-subdomains, preload)the check --deploy warning you saw is this being 0
SESSION_COOKIE_SECURE / CSRF_COOKIE_SECURETruestop cookie leak over HTTP
SECURE_CSP (Django 6.0)a real policy + noncenative CSP; pre-6.0 use django-csp
  • CSRF protection is on by default — keep CsrfViewMiddleware; do not blanket-exempt views.
  • The ORM parameterizes queries. Only .raw(), .extra() and cursor.execute() with an f-string/%-built string reopen SQL injection. Pass params, never interpolate.

Full SECURE_* checklist, CSP nonce/report-only, upload/SSRF, ORM-injection → references/security.md.

Testing

python
import pytest
from rest_framework.test import APIClient

@pytest.mark.django_db
def test_owner_only(article, owner):
    client = APIClient()
    assert client.get(f"/api/articles/{article.pk}/").status_code == 403  # anon
    client.force_authenticate(owner)
    assert client.get(f"/api/articles/{article.pk}/").status_code == 200
  • pytest-django + @pytest.mark.django_db; run with --reuse-db to skip rebuilds locally.
  • TestCase wraps each test in a rolled-back transaction (fast). Use TransactionTestCase only when you test on_commit hooks or real commit behavior.
  • Lock in N+1 fixes with assertNumQueries(2) — it fails the build when a relation regresses.
  • Build instances with factory_boy, not 30 lines of Model.objects.create(...).

Setup, fixtures, transactional DB, coverage → references/testing.md.

Background work

NeedUse
New project on Django 6.0, simple enqueue-and-forget jobsthe built-in Tasks framework
Pre-6.0, or you need schedules/retries/fan-out/result backends/workers at scaleCelery

Either way: enqueue from the model/service layer, never block the request thread.

Anti-patterns

Anti-patternWhy it bitesDo instead
Business logic in the viewuntested, duplicated across endpointsmethod on the model/manager
f-string SQL into .raw()/.extra()/cursor.executeSQL injectionparameterized queries
Looping rows touching .authorN+1 queriesselect_related/prefetch_related
DEBUG=True in prodleaks settings + stack tracesDEBUG=False in prod.py
SECRET_KEY literal in sourceforged sessions/tokensos.environ
Validation only in clean()races under concurrencyDB UniqueConstraint/CheckConstraint
Model.objects.all() in a template loopone query per iterationprefetch in the view
ModelViewSet with no permission_classesendpoint open to the worldexplicit permission class
Fat serializer walking relationsN+1 per responseprefetch + assertNumQueries
Editing an applied migrationbreaks every env that ran itnew migration
len(qs) / qs.count() to test existencefull fetch/COUNTqs.exists()
Swallowing Model.DoesNotExist silentlyhidden bugsget_object_or_404 or handle explicitly

Verify

scripts/verify.sh [TARGET] greps tracked Django source for high-signal foot-guns: FAIL on a literal SECRET_KEY, ALLOWED_HOSTS = ['*'], or f-string SQL in .raw()/.extra()/cursor.execute; WARN on DEBUG = True outside a dev settings file and a ModelViewSet/APIView with no permission_classes. Read-only, exit 0 on a clean or empty target. It is a lint, not a substitute for manage.py check --deploy or the test suite.

© ericrisco, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (scripts, references) in skills/django of ericrisco/rsc-harness.

  • SKILL.md
  • evals/README.md
  • evals/cases.yaml
  • references/drf.md
  • references/orm-performance.md
  • references/security.md
  • references/testing.md
  • scripts/verify.sh

Open the folder on GitHubat commit 92fde8f

Compare with similar skills

Django next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Django compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Django this skillericrisco/rsc-harness156—~3.1kAutomated safety check: PassMIT
Fastapi Appccplugins/awesome-claude-code-plugins967—~1.1kAutomated safety check: NotesApache-2.0
Framework Migration AssistantArabelaTso/Skills-4-SE253—~1.9kAutomated safety check: PassApache-2.0
Pydanticbobmatnyc/claude-mpm155—~8.4kAutomated safety check: NotesCustom licence
Fastcrudbenavlabs/fastcrud1.6k—~5kAutomated safety check: PassMIT
Silk Profilerbaserow/baserow6.1k—~2.9kAutomated safety check: PassCustom licence

Similar skills

  • Fastapi App

    ccplugins/awesome-claude-code-plugins

    Bootstrap a new FastAPI backend with async SQLAlchemy 2.0, asyncpg, Alembic, Pydantic v2, and no deprecated APIs.

    967 GitHub stars~1.1k tokensUpdated 1 mo ago
    Backend & APIsAuto-check: notes
  • Framework Migration Assistant

    ArabelaTso/Skills-4-SE

    Automatically migrate Python web applications between frameworks (Flask → FastAPI, Django → FastAPI).

    253 GitHub stars~1.9k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Pydantic

    bobmatnyc/claude-mpm

    Python data validation using type hints and runtime type checking with Pydantic v2's Rust-powered core for high-performance validation in FastAPI, Django, and configuration management.

    155 GitHub stars~8.4k tokensUpdated 1 mo ago
    Backend & APIsAuto-check: notes
  • Fastcrud

    benavlabs/fastcrud

    A skill your agent uses when building or modifying CRUD endpoints with FastCRUD (the fastcrud PyPI package) in a FastAPI project — covers FastCRUD, crudrouter, EndpointCreator, FilterConfig…

    1.6k GitHub stars~5k tokensUpdated 12 days ago
    Backend & APIsAuto-check passed
  • Silk Profiler

    baserow/baserow

    Investigate backend performance using Django Silk profiling data.

    6.1k GitHub stars~2.9k tokensUpdated today
    Backend & APIsAuto-check passed
  • Scaffolds FastAPI projects with a layered app layout, dependency injection through Depends, async handlers and database access, middleware and pytest setup.

    40k GitHub starsUsed in 11 repos~901 tokens
    Backend & APIsAuto-check passed

More from ericrisco/rsc-harness

All 229 skills in this repo
  • Ab Testing

    ericrisco/rsc-harness

    A skill your agent uses when designing or analyzing a controlled experiment — falsifiable hypothesis, sample size from an MDE, reading significance/CI/power, CUPED, or rescuing tests that won't go…

    156 GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Accessibility

    ericrisco/rsc-harness

    A skill your agent uses when making a web UI conform to WCAG 2.2 Level AA — axe-core or Lighthouse a11y violations, keyboard operability, focus management, ARIA roles/names/live regions, contrast…

    156 GitHub stars~3.4k tokensUpdated today
    Auto-check passed
  • Ads

    ericrisco/rsc-harness

    A skill your agent uses when running or fixing paid acquisition on Google or Meta — campaign structure (Performance Max, Demand Gen, Search, Advantage+), platform-fit creative, budget/scaling rules…

    156 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Agent Eval

    ericrisco/rsc-harness

    A skill your agent uses when measuring whether an LLM or agent system actually got better and gating merges on it: golden sets, fixing an inflated LLM-as-judge, scoring RAG (faithfulness, contextual…

    156 GitHub stars~3.2k tokensUpdated today
    Auto-check passed
  • AI Media

    ericrisco/rsc-harness

    A skill your agent uses when a creative goal must become a finished media file: pick and order generative-media models per modality — AI voiceover, image-to-video clips, score — then glue them with…

    156 GitHub stars~3.3k tokensUpdated today
    Auto-check passed
  • Analytics

    ericrisco/rsc-harness

    A skill your agent uses when instrumenting product or web analytics — GA4/PostHog SDK wiring, event taxonomy, funnels, double-counted events, consent gating, PII scrubbing.

    156 GitHub stars~2.8k tokensUpdated today
    Auto-check passed

Categories

Questions about Django

What does Django do?

A skill your agent uses when building, reviewing, securing, testing or shipping a Django app — models, migrations, QuerySets/managers, FBV/CBV views, forms, the admin, settings split, and Django…. Django is an agent skill from ericrisco/rsc-harness. Use when building, reviewing, securing, testing or shipping a Django app — models, migrations, QuerySets/managers, FBV/CBV views, forms, the admin, settings split, and Django REST Framework (serializers, ModelViewSet, permissions).

When should I use Django?

Django fits situations like: shipping a Django app — models; querySets/managers; django REST Framework (serializers.

How do I install Django in Claude Code?

Run `npx skills add ericrisco/rsc-harness --skill django -a claude-code`. Or copy the skill folder (skills/django in ericrisco/rsc-harness) into .claude/skills/django in your project. Claude Code loads it when a task matches its description.

How do I install Django in Codex?

Run `npx skills add ericrisco/rsc-harness --skill django -a codex`. Or copy the skill folder (skills/django in ericrisco/rsc-harness) into .agents/skills/django in your project. Codex loads it when a task matches its description.

Can I use Django in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ericrisco/rsc-harness --skill django -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/django, .gemini/skills/django, .github/skills/django and .opencode/skills/django in your project.

What does Django need to run?

Going by SKILL.md and its folder, Django needs a shell for the scripts in its folder, the command-line tools its instructions call (python) and credentials named SECRET_KEY. Our summary lists: Python 3; A Bash shell; A credential in SECRET_KEY.

Does Django access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Django safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Django use?

Django is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Django use?

About 3.1k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 3.3k tokens, read only when the agent opens those files.

What are the alternatives to Django?

Skills that share tags, products or a category with Django: Fastapi App (ccplugins/awesome-claude-code-plugins, 967 stars), Framework Migration Assistant (ArabelaTso/Skills-4-SE, 253 stars), Pydantic (bobmatnyc/claude-mpm, 155 stars) and Fastcrud (benavlabs/fastcrud, 1.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Django?

ericrisco (a GitHub user) maintains it in ericrisco/rsc-harness, which has 156 GitHub stars. The repository holds 229 skills in this directory. The repository was last updated on October 6, 2026.

Source: ericrisco/rsc-harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.