PluginBench
Skill
Fail
Audit score 45

django-expert

jeffallan/claude-skills

Senior Django specialist for building optimized REST APIs, models, and production-grade web applications.

What is django-expert?

Expert guidance for Django 5.0 and Django REST Framework projects. Use when designing models, building DRF serializers and viewsets, optimizing ORM queries, or configuring authentication. Covers models with indexes, query optimization via select_related/prefetch_related, JWT authentication, and testing.

  • Creates Django models with proper field indexes and relationships
  • Optimizes ORM queries using select_related and prefetch_related to prevent N+1 problems
  • Builds DRF serializers with validation and viewsets with proper permissions
  • Configures JWT authentication and permission classes for API endpoints
  • Generates APITestCase tests for models and endpoints
  • Customizes Django admin and implements async views

How to install django-expert

npx skills add https://github.com/jeffallan/claude-skills --skill django-expert
Prerequisites
  • Django 5.0 or compatible version installed
  • Django REST Framework package
  • SimpleJWT for token authentication (optional but recommended)
  • pytest-django for testing (optional)
Claude Code
Cursor
Windsurf
Cline

How to use django-expert

  1. 1.Analyze your project requirements and identify models, relationships, and API endpoints
  2. 2.Define Django models with proper fields, indexes, and relationships using the provided model patterns
  3. 3.Run `manage.py makemigrations` and `manage.py migrate` to apply schema changes
  4. 4.Implement DRF serializers with field validation matching your model structure
  5. 5.Create viewsets or views with appropriate permission classes and query optimization
  6. 6.Add JWT authentication configuration to settings.py if needed
  7. 7.Write APITestCase tests to validate endpoints return correct status codes and data
  8. 8.Deploy using environment variables for secrets and DEBUG=False in production

Use cases

Good for
  • Building a REST API with DRF serializers, viewsets, and JWT authentication
  • Designing a multi-model application with optimized database queries and indexes
  • Implementing user authentication and permission-based access control on endpoints
  • Writing comprehensive tests for Django models and API endpoints
  • Migrating or refactoring existing Django projects to follow best practices
Who it's for
  • Backend developers building Django web applications
  • API developers using Django REST Framework
  • Full-stack engineers setting up Django projects with authentication
  • Teams needing production-grade Django architecture and optimization

django-expert FAQ

When should I use select_related vs prefetch_related?

Use select_related for ForeignKey and OneToOneField relationships (single object lookup); use prefetch_related for ManyToManyField and reverse ForeignKey relationships (multiple objects). Both prevent N+1 queries.

How do I add JWT authentication to my API?

Install SimpleJWT, add it to INSTALLED_APPS and MIDDLEWARE in settings.py, configure REST_FRAMEWORK authentication classes, and use the provided authentication reference guide in the skill.

What database indexes should I add to my models?

Add db_index=True to fields frequently used in WHERE clauses or filters (like author, published_at). Use Meta.indexes for composite indexes on multiple fields queried together.

How do I ensure my API endpoints are secure?

Always use permission_classes on viewsets (e.g., IsAuthenticatedOrReadOnly), validate user input in serializers, use CSRF protection, parameterize queries, and never store secrets in settings.py.

Should I write tests before or after implementing views?

Write tests after implementing basic views to validate they return correct status codes and data. Use APITestCase for endpoint tests and TestCase for model tests.

Full instructions (SKILL.md)

Source of truth, from jeffallan/claude-skills.


name: django-expert description: "Use when building Django web applications or REST APIs with Django REST Framework. Invoke when working with settings.py, models.py, manage.py, or any Django project file. Creates Django models with proper indexes, optimizes ORM queries using select_related/prefetch_related, builds DRF serializers and viewsets, and configures JWT authentication. Trigger terms: Django, DRF, Django REST Framework, Django ORM, Django model, serializer, viewset, Python web." license: MIT metadata: author: https://github.com/Jeffallan version: "1.1.0" domain: backend triggers: Django, DRF, Django REST Framework, Django ORM, Django model, serializer, viewset, Python web role: specialist scope: implementation output-format: code related-skills: fullstack-guardian, fastapi-expert, test-master, django-storages-s3

Django Expert

Senior Django specialist with deep expertise in Django 5.0, Django REST Framework, and production-grade web applications.

When to Use This Skill

  • Building Django web applications or REST APIs
  • Designing Django models with proper relationships
  • Implementing DRF serializers and viewsets
  • Optimizing Django ORM queries
  • Setting up authentication (JWT, session)
  • Django admin customization

Core Workflow

  1. Analyze requirements — Identify models, relationships, API endpoints
  2. Design models — Create models with proper fields, indexes, managers → run manage.py makemigrations and manage.py migrate; verify schema before proceeding
  3. Implement views — DRF viewsets or Django 5.0 async views
  4. Validate endpoints — Confirm each endpoint returns expected status codes with a quick APITestCase or curl check before adding auth
  5. Add auth — Permissions, JWT authentication
  6. Test — Django TestCase, APITestCase

Reference Guide

Load detailed guidance based on context:

TopicReferenceLoad When
Modelsreferences/models-orm.mdCreating models, ORM queries, optimization
Serializersreferences/drf-serializers.mdDRF serializers, validation
ViewSetsreferences/viewsets-views.mdViews, viewsets, async views
Authenticationreferences/authentication.mdJWT, permissions, SimpleJWT
Testingreferences/testing-django.mdAPITestCase, fixtures, factories

Minimal Working Example

The snippet below demonstrates the core MUST DO constraints: indexed fields, select_related, serializer validation, and endpoint permissions.

# models.py
from django.db import models

class Article(models.Model):
    title = models.CharField(max_length=255, db_index=True)
    author = models.ForeignKey(
        "auth.User", on_delete=models.CASCADE, related_name="articles"
    )
    published_at = models.DateTimeField(auto_now_add=True, db_index=True)

    class Meta:
        ordering = ["-published_at"]
        indexes = [models.Index(fields=["author", "published_at"])]

    def __str__(self):
        return self.title

# serializers.py
from rest_framework import serializers
from .models import Article

class ArticleSerializer(serializers.ModelSerializer):
    author_username = serializers.CharField(source="author.username", read_only=True)

    class Meta:
        model = Article
        fields = ["id", "title", "author_username", "published_at"]

    def validate_title(self, value):
        if len(value.strip()) < 3:
            raise serializers.ValidationError("Title must be at least 3 characters.")
        return value.strip()

# views.py
from rest_framework import viewsets, permissions
from .models import Article
from .serializers import ArticleSerializer

class ArticleViewSet(viewsets.ModelViewSet):
    """
    Uses select_related to avoid N+1 on author lookups.
    IsAuthenticatedOrReadOnly: safe methods are public, writes require auth.
    """
    serializer_class = ArticleSerializer
    permission_classes = [permissions.IsAuthenticatedOrReadOnly]

    def get_queryset(self):
        return Article.objects.select_related("author").all()

    def perform_create(self, serializer):
        serializer.save(author=self.request.user)
# tests.py
from rest_framework.test import APITestCase
from rest_framework import status
from django.contrib.auth.models import User

class ArticleAPITest(APITestCase):
    def setUp(self):
        self.user = User.objects.create_user("alice", password="pass")

    def test_list_public(self):
        res = self.client.get("/api/articles/")
        self.assertEqual(res.status_code, status.HTTP_200_OK)

    def test_create_requires_auth(self):
        res = self.client.post("/api/articles/", {"title": "Test"})
        self.assertEqual(res.status_code, status.HTTP_403_FORBIDDEN)

    def test_create_authenticated(self):
        self.client.force_authenticate(self.user)
        res = self.client.post("/api/articles/", {"title": "Hello Django"})
        self.assertEqual(res.status_code, status.HTTP_201_CREATED)

Constraints

MUST DO

  • Use select_related/prefetch_related for related objects
  • Add database indexes for frequently queried fields
  • Use environment variables for secrets
  • Implement proper permissions on all endpoints
  • Write tests for models and API endpoints
  • Use Django's built-in security features (CSRF, etc.)

MUST NOT DO

  • Use raw SQL without parameterization
  • Skip database migrations
  • Store secrets in settings.py
  • Use DEBUG=True in production
  • Trust user input without validation
  • Ignore query optimization

Output Templates

When implementing Django features, provide:

  1. Model definitions with indexes
  2. Serializers with validation
  3. ViewSet or views with permissions
  4. Brief note on query optimization

Knowledge Reference

Django 5.0, DRF, async views, ORM, QuerySet, select_related, prefetch_related, SimpleJWT, django-filter, drf-spectacular, pytest-django

Documentation