Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Verification loop for Django projects: migrations, linting, tests with coverage, security scans, and deployment readiness checks before release or PR.
.claude/skills/loulanyue-django-verification/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-06 | ✗→✓ | ▲ Improved | 174% | 0% |
| case-09 | ✗→✓ | ▲ Improved | 326% | 0% |
| case-12 | ✗→✓ | ▲ Improved | 781% | 0% |
| case-15 | ✗→✓ | ▲ Improved | 239% | 0% |
| case-16 | ✗→✓ | ▲ Improved | 178% | 0% |
Run before PRs, after major changes, and pre-deploy to ensure Django application quality and security.
bash# Verify Python version python --version # Should match project requirements # Check virtual environment which python pip list --outdated # Verify environment variables python -c "import os; import environ; print('DJANGO_SECRET_KEY set' if os.environ.get('DJANGO_SECRET_KEY') else 'MISSING: DJANGO_SECRET_KEY')"
If environment is misconfigured, stop and fix.
bash# Type checking mypy . --config-file pyproject.toml # Linting with ruff ruff check . --fix # Formatting with black black . --check black . # Auto-fix # Import sorting isort . --check-only isort . # Auto-fix # Django-specific checks python manage.py check --deploy
Common issues:
bash# Check for unapplied migrations python manage.py showmigrations # Create missing migrations python manage.py makemigrations --check # Dry-run migration application python manage.py migrate --plan # Apply migrations (test environment) python manage.py migrate # Check for migration conflicts python manage.py makemigrations --merge # Only if conflicts exist
Report:
bash# Run all tests with pytest pytest --cov=apps --cov-report=html --cov-report=term-missing --reuse-db # Run specific app tests pytest apps/users/tests/ # Run with markers pytest -m "not slow" # Skip slow tests pytest -m integration # Only integration tests # Coverage report open htmlcov/index.html
Report:
Coverage targets:
| Component | Target | |-----------|--------| | Models | 90%+ | | Serializers | 85%+ | | Views | 80%+ | | Services | 90%+ | | Overall | 80%+ |
bash# Dependency vulnerabilities pip-audit safety check --full-report # Django security checks python manage.py check --deploy # Bandit security linter bandit -r . -f json -o bandit-report.json # Secret scanning (if gitleaks is installed) gitleaks detect --source . --verbose # Environment variable check python -c "from django.core.exceptions import ImproperlyConfigured; from django.conf import settings; settings.DEBUG"
Report:
bash# Check for model issues python manage.py check # Collect static files python manage.py collectstatic --noinput --clear # Create superuser (if needed for tests) echo "from apps.users.models import User; User.objects.create_superuser('admin@example.com', 'admin')" | python manage.py shell # Database integrity python manage.py check --database default # Cache verification (if using Redis) python -c "from django.core.cache import cache; cache.set('test', 'value', 10); print(cache.get('test'))"
bash# Django Debug Toolbar output (check for N+1 queries) # Run in dev mode with DEBUG=True and access a page # Look for duplicate queries in SQL panel # Query count analysis django-admin debugsqlshell # If django-debug-sqlshell installed # Check for missing indexes python manage.py shell << EOF from django.db import connection with connection.cursor() as cursor: cursor.execute("SELECT table_name, index_name FROM information_schema.statistics WHERE table_schema = 'public'") print(cursor.fetchall()) EOF
Report:
bash# Check for npm dependencies (if using npm) npm audit npm audit fix # Build static files (if using webpack/vite) npm run build # Verify static files ls -la staticfiles/ python manage.py findstatic css/style.css
python# Run in Python shell to verify settings python manage.py shell << EOF from django.conf import settings import os # Critical checks checks = { 'DEBUG is False': not settings.DEBUG, 'SECRET_KEY set': bool(settings.SECRET_KEY and len(settings.SECRET_KEY) > 30), 'ALLOWED_HOSTS set': len(settings.ALLOWED_HOSTS) > 0, 'HTTPS enabled': getattr(settings, 'SECURE_SSL_REDIRECT', False), 'HSTS enabled': getattr(settings, 'SECURE_HSTS_SECONDS', 0) > 0, 'Database configured': settings.DATABASES['default']['ENGINE'] != 'django.db.backends.sqlite3', } for check, result in checks.items(): status = '✓' if result else '✗' print(f"{status} {check}") EOF
bash# Test logging output python manage.py shell << EOF import logging logger = logging.getLogger('django') logger.warning('Test warning message') logger.error('Test error message') EOF # Check log files (if configured) tail -f /var/log/django/django.log
bash# Generate schema python manage.py generateschema --format openapi-json > schema.json # Validate schema # Check if schema.json is valid JSON python -c "import json; json.load(open('schema.json'))" # Access Swagger UI (if using drf-yasg) # Visit http://localhost:8000/swagger/ in browser
bash# Show diff statistics git diff --stat # Show actual changes git diff # Show changed files git diff --name-only # Check for common issues git diff | grep -i "todo\|fixme\|hack\|xxx" git diff | grep "print(" # Debug statements git diff | grep "DEBUG = True" # Debug mode git diff | grep "import pdb" # Debugger
Checklist:
DJANGO VERIFICATION REPORT
==========================
Phase 1: Environment Check
✓ Python 3.11.5
✓ Virtual environment active
✓ All environment variables set
Phase 2: Code Quality
✓ mypy: No type errors
✗ ruff: 3 issues found (auto-fixed)
✓ black: No formatting issues
✓ isort: Imports properly sorted
✓ manage.py check: No issues
Phase 3: Migrations
✓ No unapplied migrations
✓ No migration conflicts
✓ All models have migrations
Phase 4: Tests + Coverage
Tests: 247 passed, 0 failed, 5 skipped
Coverage:
Overall: 87%
users: 92%
products: 89%
orders: 85%
payments: 91%
Phase 5: Security Scan
✗ pip-audit: 2 vulnerabilities found (fix required)
✓ safety check: No issues
✓ bandit: No security issues
✓ No secrets detected
✓ DEBUG = False
Phase 6: Django Commands
✓ collectstatic completed
✓ Database integrity OK
✓ Cache backend reachable
Phase 7: Performance
✓ No N+1 queries detected
✓ Database indexes configured
✓ Query count acceptable
Phase 8: Static Assets
✓ npm audit: No vulnerabilities
✓ Assets built successfully
✓ Static files collected
Phase 9: Configuration
✓ DEBUG = False
✓ SECRET_KEY configured
✓ ALLOWED_HOSTS set
✓ HTTPS enabled
✓ HSTS enabled
✓ Database configured
Phase 10: Logging
✓ Logging configured
✓ Log files writable
Phase 11: API Documentation
✓ Schema generated
✓ Swagger UI accessible
Phase 12: Diff Review
Files changed: 12
+450, -120 lines
✓ No debug statements
✓ No hardcoded secrets
✓ Migrations included
RECOMMENDATION: ⚠️ Fix pip-audit vulnerabilities before deploying
NEXT STEPS:
1. Update vulnerable dependencies
2. Re-run security scan
3. Deploy to staging for final testingyaml# .github/workflows/django-verification.yml name: Django Verification on: [push, pull_request] jobs: verify: runs-on: ubuntu-latest services: postgres: image: postgres:14 env: POSTGRES_PASSWORD: postgres options: >- --health-cmd pg_isready --health-interval 10s --health-timeout 5s --health-retries 5 steps: - uses: actions/checkout@v3 - name: Set up Python uses: actions/setup-python@v4 with: python-version: '3.11' - name: Cache pip uses: actions/cache@v3 with: path: ~/.cache/pip key: ${{ runner.os }}-pip-${{ hashFiles('**/requirements.txt') }} - name: Install dependencies run: | pip install -r requirements.txt pip install ruff black mypy pytest pytest-django pytest-cov bandit safety pip-audit - name: Code quality checks run: | ruff check . black . --check isort . --check-only mypy . - name: Security scan run: | bandit -r . -f json -o bandit-report.json safety check --full-report pip-audit - name: Run tests env: DATABASE_URL: postgres://postgres:postgres@localhost:5432/test DJANGO_SECRET_KEY: test-secret-key run: | pytest --cov=apps --cov-report=xml --cov-report=term-missing - name: Upload coverage uses: codecov/codecov-action@v3
| Check | Command | |-------|---------| | Environment | python --version | | Type checking | mypy . | | Linting | ruff check . | | Formatting | black . --check | | Migrations | python manage.py makemigrations --check | | Tests | pytest --cov=apps | | Security | pip-audit && bandit -r . | | Django check | python manage.py check --deploy | | Collectstatic | python manage.py collectstatic --noinput | | Diff stats | git diff --stat |
Remember: Automated verification catches common issues but doesn't replace manual code review and testing in staging environment.
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-01 | fail→fail | 37,307 | 16,903 | -55% | 1 | 1 | 0% | 3,505 | 6,103 | +74% | 0 | 0 | — |
case-02 | fail→fail | 19,620 | 20,480 | +4% | 1 | 1 | 0% | 3,545 | 6,221 | +75% | 0 | 0 | — |
case-03 | fail→fail | 28,278 | 16,392 | -42% | 1 | 1 | 0% | 5,199 | 6,036 | +16% | 0 | 0 | — |
case-04 | pass→pass | 16,110 | 3,082 | -81% | 1 | 1 | 0% | 2,568 | 3,529 | +37% | 0 | 0 | — |
case-05 | pass→pass | 14,422 | 4,627 | -68% | 1 | 1 | 0% | 2,405 | 3,811 | +58% | 0 | 0 | — |
case-06 | fail→pass | 6,911 | 1,973 | -71% | 1 | 1 | 0% | 1,227 | 3,363 | +174% | 0 | 0 | — |
case-07 | pass→pass | 3,022 | 2,587 | -14% | 1 | 1 | 0% | 421 | 3,477 | +726% | 0 | 0 | — |
case-08 | pass→pass | 8,525 | 8,426 | -1% | 1 | 1 | 0% | 1,384 | 4,445 | +221% | 0 | 0 | — |
case-09 | fail→pass | 4,633 | 1,670 | -64% | 1 | 1 | 0% | 780 | 3,326 | +326% | 0 | 0 | — |
case-10 | pass→pass | 13,313 | 11,501 | -14% | 1 | 1 | 0% | 2,157 | 5,022 | +133% | 0 | 0 | — |
case-11 | fail→fail | 8,719 | 6,907 | -21% | 1 | 1 | 0% | 1,830 | 4,483 | +145% | 0 | 0 | — |
case-12 | fail→pass | 2,528 | 2,192 | -13% | 1 | 1 | 0% | 386 | 3,400 | +781% | 0 | 0 | — |
case-13 | fail→fail | 8,296 | 5,342 | -36% | 1 | 1 | 0% | 1,460 | 4,010 | +175% | 0 | 0 | — |
case-14 | pass→pass | 10,923 | 5,198 | -52% | 1 | 1 | 0% | 1,949 | 3,988 | +105% | 0 | 0 | — |
case-19 | pass→pass | 13,947 | 13,609 | -2% | 1 | 1 | 0% | 2,227 | 5,536 | +149% | 0 | 0 | — |
case-15 | fail→pass | 5,867 | 1,279 | -78% | 1 | 1 | 0% | 949 | 3,214 | +239% | 0 | 0 | — |
case-16 | fail→pass | 8,782 | 7,433 | -15% | 1 | 1 | 0% | 1,493 | 4,154 | +178% | 0 | 0 | — |
case-17 | pass→pass | 3,689 | 2,611 | -29% | 1 | 1 | 0% | 504 | 3,487 | +592% | 0 | 0 | — |
case-18 | pass→pass | 5,521 | 1,782 | -68% | 1 | 1 | 0% | 920 | 3,277 | +256% | 0 | 0 | — |
case-20 | pass→pass | 11,060 | 11,677 | +6% | 1 | 1 | 0% | 1,979 | 5,248 | +165% | 0 | 0 | — |
case-21 | pass→pass | 14,523 | 15,996 | +10% | 1 | 1 | 0% | 2,783 | 6,314 | +127% | 0 | 0 | — |
case-22 | pass→pass | 9,074 | 7,956 | -12% | 1 | 1 | 0% | 1,742 | 4,615 | +165% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 22 cases were attempted. The headline lift of +23 percentage points is the difference between those two pass rates over the 22 comparable cases.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.