Official agent skill

Django Access Review

by getsentry in getsentry/skills

Django access control and IDOR security review. An agent skill from getsentry/skills.

OfficialApache-2.0Auto-check: notesBackend & APIs

Install Django Access Review

skills CLI
$ npx skills add getsentry/skills --skill django-access-review -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install getsentry/skills django-access-review --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/getsentry/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/django-access-review .claude/skills/django-access-review && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
django-access-review
GitHub stars
1k
Used in
3 other repos
Token cost
~2.6k tokens
SKILL.md length
425 words
Files
5 (incl. references)
Skills in repo
27
Repo updated
First seen
Licence
Apache-2.0

At a glance

Django access control and IDOR security review. An agent skill from getsentry/skills.

  • Works in 5 steps: Understand the Authorization Model → Map the Attack Surface → Ask Questions and Investigate → …
  • Reviewing Django views
  • SKILL.md covers Philosophy: Investigation Over…, Phase 1: Understand the…, Phase 2: Map the Attack Surface and Phase 3: Ask Questions and…, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Django Access Review is an agent skill from getsentry/skills, published by the product's own GitHub organization. Django access control and IDOR security review. Use when reviewing Django views, DRF viewsets, ORM queries, or any Python/Django code handling user authorization. Trigger keywords: "IDOR", "access control", "authorization", "Django permissions", "object permissions", "tenant isolation", "broken access".

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `references/django-orm.md`, `references/django-views.md` and `references/drf-permissions.md`).

It sits in Backend & APIs, covering Backend development, Authorization and RBAC and Web application vulnerabilities. It works with Django and Python. The repository describes itself as: Agent Skills used by the Sentry team for development. The licence is Apache-2.0.

When your agent uses it

  • Reviewing Django views
  • Any Python/Django code handling user authorization
  • Django permissions
  • Object permissions

Example prompts

  • “access control”
  • “authorization”
  • “Django permissions”
  • “/django-access-review”

Requirements

  • Python 3
  • Pre-approved tools (allowed-tools): Read, Grep, Glob, Bash, Task

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Understand the Authorization Model
  2. Map the Attack Surface
  3. Ask Questions and Investigate
  4. Trace Specific Flows
  5. Report Findings

What it can do on your machine

Read from SKILL.md and the folder at commit d18b7aa. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Grep
    • Glob
    • Bash
    • Task

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are python, bash and markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • cheatsheetseries.owasp.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Django Access Review loads about 2.6k tokens when it runs, and up to ~4.4k if it reads all its reference files. Until then it costs about 81 tokens; SKILL.md has 425 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~81
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Grep, Glob, Bash, Task

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from getsentry/skills at commit d18b7aa, republished under its Apache-2.0 licence (© getsentry). 425 words, ~2,554 tokens.

Download SKILL.mdSave it as .claude/skills/django-access-review/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
django-access-review
description
Django access control and IDOR security review. Use when reviewing Django views, DRF viewsets, ORM queries, or any Python/Django code handling user authorization. Trigger keywords: "IDOR", "access control", "authorization", "Django permissions", "object permissions", "tenant isolation", "broken access".
allowed-tools
Read, Grep, Glob, Bash, Task
license
LICENSE
<!--
Reference material based on OWASP Cheat Sheet Series (CC BY-SA 4.0)
https://cheatsheetseries.owasp.org/
-->

Django Access Control & IDOR Review

Find access control vulnerabilities by investigating how the codebase answers one question:

Can User A access, modify, or delete User B's data?

Philosophy: Investigation Over Pattern Matching

Do NOT scan for predefined vulnerable patterns. Instead:

  1. Understand how authorization works in THIS codebase
  2. Ask questions about specific data flows
  3. Trace code to find where (or if) access checks happen
  4. Report only what you've confirmed through investigation

Every codebase implements authorization differently. Your job is to understand this specific implementation, then find gaps.


Phase 1: Understand the Authorization Model

Before looking for bugs, answer these questions about the codebase:

How is authorization enforced?

Research the codebase to find:

□ Where are permission checks implemented?
  - Decorators? (@login_required, @permission_required, custom?)
  - Middleware? (TenantMiddleware, AuthorizationMiddleware?)
  - Base classes? (BaseAPIView, TenantScopedViewSet?)
  - Permission classes? (DRF permission_classes?)
  - Custom mixins? (OwnershipMixin, TenantMixin?)

□ How are queries scoped?
  - Custom managers? (TenantManager, UserScopedManager?)
  - get_queryset() overrides?
  - Middleware that sets query context?

□ What's the ownership model?
  - Single user ownership? (document.owner_id)
  - Organization/tenant ownership? (document.organization_id)
  - Hierarchical? (org -> team -> user -> resource)
  - Role-based within context? (org admin vs member)
Investigation commands
bash
# Find how auth is typically done
grep -rn "permission_classes\|@login_required\|@permission_required" --include="*.py" | head -20

# Find base classes that views inherit from
grep -rn "class Base.*View\|class.*Mixin.*:" --include="*.py" | head -20

# Find custom managers
grep -rn "class.*Manager\|def get_queryset" --include="*.py" | head -20

# Find ownership fields on models
grep -rn "owner\|user_id\|organization\|tenant" --include="models.py" | head -30

Do not proceed until you understand the authorization model.


Phase 2: Map the Attack Surface

Identify endpoints that handle user-specific data:

What resources exist?
□ What models contain user data?
□ Which have ownership fields (owner_id, user_id, organization_id)?
□ Which are accessed via ID in URLs or request bodies?
What operations are exposed?

For each resource, map:

  • List endpoints - what data is returned?
  • Detail/retrieve endpoints - how is the object fetched?
  • Create endpoints - who sets the owner?
  • Update endpoints - can users modify others' data?
  • Delete endpoints - can users delete others' data?
  • Custom actions - what do they access?

Phase 3: Ask Questions and Investigate

For each endpoint that handles user data, ask:

The Core Question

"If I'm User A and I know the ID of User B's resource, can I access it?"

Trace the code to answer this:

1. Where does the resource ID enter the system?
   - URL path: /api/documents/{id}/
   - Query param: ?document_id=123
   - Request body: {"document_id": 123}

2. Where is that ID used to fetch data?
   - Find the ORM query or database call

3. Between (1) and (2), what checks exist?
   - Is the query scoped to current user?
   - Is there an explicit ownership check?
   - Is there a permission check on the object?
   - Does a base class or mixin enforce access?

4. If you can't find a check, is there one you missed?
   - Check parent classes
   - Check middleware
   - Check managers
   - Check decorators at URL level
Follow-Up Questions
□ For list endpoints: Does the query filter to user's data, or return everything?

□ For create endpoints: Who sets the owner - the server or the request?

□ For bulk operations: Are they scoped to user's data?

□ For related resources: If I can access a document, can I access its comments?
  What if the document belongs to someone else?

□ For tenant/org resources: Can User in Org A access Org B's data by changing
  the org_id in the URL?

Phase 4: Trace Specific Flows

Pick a concrete endpoint and trace it completely.

Example Investigation
Endpoint: GET /api/documents/{pk}/

1. Find the view handling this URL
   → DocumentViewSet.retrieve() in api/views.py

2. Check what DocumentViewSet inherits from
   → class DocumentViewSet(viewsets.ModelViewSet)
   → No custom base class with authorization

3. Check permission_classes
   → permission_classes = [IsAuthenticated]
   → Only checks login, not ownership

4. Check get_queryset()
   → def get_queryset(self):
   →     return Document.objects.all()
   → Returns ALL documents!

5. Check for has_object_permission()
   → Not implemented

6. Check retrieve() method
   → Uses default, which calls get_object()
   → get_object() uses get_queryset(), which returns all

7. Conclusion: IDOR - Any authenticated user can access any document
What to look for when tracing
Potential gap indicators (investigate further, don't auto-flag):
- get_queryset() returns .all() or filters without user
- Direct Model.objects.get(pk=pk) without ownership in query
- ID comes from request body for sensitive operations
- Permission class checks auth but not ownership
- No has_object_permission() and queryset isn't scoped

Likely safe patterns (but verify the implementation):
- get_queryset() filters by request.user or user's org
- Custom permission class with has_object_permission()
- Base class that enforces scoping
- Manager that auto-filters

Show full SKILL.md (174 more words)Show less

Phase 5: Report Findings

Only report issues you've confirmed through investigation.

Confidence Levels
LevelMeaningAction
HIGHTraced the flow, confirmed no check existsReport with evidence
MEDIUMCheck may exist but couldn't confirmNote for manual verification
LOWTheoretical, likely mitigatedDo not report
Suggested Fixes Must Enforce, Not Document

Bad fix: Adding a comment saying "caller must validate permissions" Good fix: Adding code that actually validates permissions

A comment or docstring does not enforce authorization. Your suggested fix must include actual code that:

  • Validates the user has permission before proceeding
  • Raises an exception or returns an error if unauthorized
  • Makes unauthorized access impossible, not just discouraged

Example of a BAD fix suggestion:

python
def get_resource(resource_id):
    # IMPORTANT: Caller must ensure user has access to this resource
    return Resource.objects.get(pk=resource_id)

Example of a GOOD fix suggestion:

python
def get_resource(resource_id, user):
    resource = Resource.objects.get(pk=resource_id)
    if resource.owner_id != user.id:
        raise PermissionDenied("Access denied")
    return resource

If you can't determine the right enforcement mechanism, say so - but never suggest documentation as the fix.

Report Format
markdown
## Access Control Review: [Component]

### Authorization Model
[Brief description of how this codebase handles authorization]

### Findings

#### [IDOR-001] [Title] (Severity: High/Medium)
- **Location**: `path/to/file.py:123`
- **Confidence**: High - confirmed through code tracing
- **The Question**: Can User A access User B's documents?
- **Investigation**:
  1. Traced GET /api/documents/{pk}/ to DocumentViewSet
  2. Checked get_queryset() - returns Document.objects.all()
  3. Checked permission_classes - only IsAuthenticated
  4. Checked for has_object_permission() - not implemented
  5. Verified no relevant middleware or base class checks
- **Evidence**: [Code snippet showing the gap]
- **Impact**: Any authenticated user can read any document by ID
- **Suggested Fix**: [Code that enforces authorization - NOT a comment]

### Needs Manual Verification
[Issues where authorization exists but couldn't confirm effectiveness]

### Areas Not Reviewed
[Endpoints or flows not covered in this review]

Common Django Authorization Patterns

These are patterns you might find - not a checklist to match against.

Query Scoping
python
# Scoped to user
Document.objects.filter(owner=request.user)

# Scoped to organization
Document.objects.filter(organization=request.user.organization)

# Using a custom manager
Document.objects.for_user(request.user)  # Investigate what this does
Permission Enforcement
python
# DRF permission classes
permission_classes = [IsAuthenticated, IsOwner]

# Custom has_object_permission
def has_object_permission(self, request, view, obj):
    return obj.owner == request.user

# Django decorators
@permission_required('app.view_document')

# Manual checks
if document.owner != request.user:
    raise PermissionDenied()
Ownership Assignment
python
# Server-side (safe)
def perform_create(self, serializer):
    serializer.save(owner=self.request.user)

# From request (investigate)
serializer.save(**request.data)  # Does request.data include owner?

Investigation Checklist

Use this to guide your review, not as a pass/fail checklist:

□ I understand how authorization is typically implemented in this codebase
□ I've identified the ownership model (user, org, tenant, etc.)
□ I've mapped the key endpoints that handle user data
□ For each sensitive endpoint, I've traced the flow and asked:
  - Where does the ID come from?
  - Where is data fetched?
  - What checks exist between input and data access?
□ I've verified my findings by checking parent classes and middleware
□ I've only reported issues I've confirmed through investigation

© getsentry, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (references) in skills/django-access-review of getsentry/skills.

  • SKILL.md
  • references/django-orm.md
  • references/django-views.md
  • references/drf-permissions.md
  • references/tenant-isolation.md

Open the folder on GitHubat commit d18b7aa

Used in 3 other repositories

We found 14 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 3 other GitHub owners. This page covers the copy in getsentry/skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Django Access Review next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Django Access Review compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Django Access Review this skillgetsentry/skills1k3 repos~2.6kAutomated safety check: NotesApache-2.0
Django Securityaffaan-m/ECC275k5 repos~4kAutomated safety check: NotesMIT
Django Securityaffaan-m/ECC275k1 repos~4.3kAutomated safety check: NotesMIT
Python Web App Security Auditaiskillstore/marketplace430—~1.2kAutomated safety check: NotesMIT
Php Framework Auditwgpsec/AboutSecurity1.8k—~767Automated safety check: NotesNone
Security Reviewlangfuse/langfuse36k—~1.4kAutomated safety check: PassCustom licence

Similar skills

  • Django Security

    affaan-m/ECC

    Django security best practices, authentication, authorization, CSRF protection, SQL injection prevention, XSS prevention, and secure deployment configurations.

    275k GitHub starsUsed in 5 repos~4k tokens
    Backend & APIsAuto-check: notes
  • Django Security

    affaan-m/ECC

    Django security best practices, authentication, authorization, CSRF protection, SQL injection prevention, XSS prevention, and secure deployment configurations.

    275k GitHub starsUsed in 1 repo~4.3k tokens
    Backend & APIsAuto-check: notes
  • Python Web App Security Audit

    aiskillstore/marketplace

    Run defensive pre-release security tests for Python web applications.

    430 GitHub stars~1.2k tokensUpdated yesterday
    Backend & APIsAuto-check: notes
  • Php Framework Audit

    wgpsec/AboutSecurity

    PHP 框架特定安全审计。当在 PHP 白盒审计中已识别目标使用特定框架、 需要检查框架特有安全机制和常见配置缺陷时触发。

    1.8k GitHub stars~767 tokensUpdated 5 days ago
    Backend & APIsAuto-check: notes
  • Security Review

    langfuse/langfuse

    Review Langfuse changes for SSRF, tenant isolation, secret handling, unsafe redirects or uploads, RBAC drift, and client telemetry privacy.

    36k GitHub stars~1.4k tokensUpdated today
    SecurityAuto-check passed
  • Django Expert

    Jeffallan/claude-skills

    Builds Django apps and Django REST Framework APIs: models with indexes, ORM query optimization, serializers, viewsets and JWT authentication, with tests.

    12k GitHub stars~1.5k tokensUpdated 5 days ago
    Backend & APIsAuto-check passed

More from getsentry/skills

All 27 skills in this repo
  • Gh Review Requests

    getsentry/skills

    Official

    Fetch unread GitHub notifications for open PRs where review is requested from a specified team or opened by a team member.

    1k GitHub starsUsed in 4 repos~621 tokens
    Auto-check: notes
  • Skill Scanner

    getsentry/skills

    Official

    Scan agent skills for security issues. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.5k tokens
    Auto-check: warnings
  • Security Review

    getsentry/skills

    Official

    Security code review for vulnerabilities. An agent skill from getsentry/skills.

    1k GitHub starsUsed in 4 repos~2.9k tokens
    Auto-check: notes
  • Skill Writer

    getsentry/skills

    Official

    Create, synthesize, and iteratively improve agent skills following the Agent Skills specification.

    1k GitHub stars~2.5k tokensUpdated 5 days ago
    Auto-check passed
  • Gha Security Review

    getsentry/skills

    Official

    GitHub Actions security review for workflow exploitation vulnerabilities.

    1k GitHub starsUsed in 3 repos~2.2k tokens
    Auto-check: notes
  • Code Simplifier

    getsentry/skills

    Official

    Simplifies and refines code for clarity, consistency, and maintainability while preserving all functionality.

    1k GitHub starsUsed in 6 repos~991 tokens
    Auto-check passed

Works with

Questions about Django Access Review

What does Django Access Review do?

Django access control and IDOR security review. An agent skill from getsentry/skills. Django Access Review is an agent skill from getsentry/skills, published by the product's own GitHub organization. Django access control and IDOR security review.

When should I use Django Access Review?

Django Access Review fits situations like: reviewing Django views; any Python/Django code handling user authorization; django permissions; object permissions.

How do I install Django Access Review in Claude Code?

Run `npx skills add getsentry/skills --skill django-access-review -a claude-code`. Or copy the skill folder (skills/django-access-review in getsentry/skills) into .claude/skills/django-access-review in your project. Claude Code loads it when a task matches its description.

How do I install Django Access Review in Codex?

Run `npx skills add getsentry/skills --skill django-access-review -a codex`. Or copy the skill folder (skills/django-access-review in getsentry/skills) into .agents/skills/django-access-review in your project. Codex loads it when a task matches its description.

Can I use Django Access Review in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add getsentry/skills --skill django-access-review -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/django-access-review, .gemini/skills/django-access-review, .github/skills/django-access-review and .opencode/skills/django-access-review in your project.

What does Django Access Review need to run?

SKILL.md names no scripts, command-line tools or credentials: Django Access Review is instructions for the agent only. Our summary lists: Python 3. Its frontmatter pre-approves these tools: Read, Grep, Glob, Bash, Task.

Does Django Access Review access the network?

SKILL.md names 1 domain. As links in the text: cheatsheetseries.owasp.org. This is read from the text; nothing was executed.

Is Django Access Review safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Django Access Review use?

Django Access Review is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Django Access Review use?

About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.8k tokens, read only when the agent opens those files.

What are the alternatives to Django Access Review?

Skills that share tags, products or a category with Django Access Review: Django Security (affaan-m/ECC, 275k stars), Django Security (affaan-m/ECC, 275k stars), Python Web App Security Audit (aiskillstore/marketplace, 430 stars) and Php Framework Audit (wgpsec/AboutSecurity, 1.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Django Access Review?

getsentry (a GitHub organization, an official publisher) maintains it in getsentry/skills, which has 1,038 GitHub stars. The repository holds 27 skills in this directory. The repository was last updated on October 2, 2026.

Source: getsentry/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.