Skip to content
Back to skills

Jinja2 Prompts

ASecurity

Parameterized prompt templates using Jinja2 patterns for reusable, dynamic agent prompts

  • 15 stars
  • 0 votes
  • 0 copies
  • 9 views
  • Added September 12, 2026
ai-agentsnodesecurity

Security analysis

A100/100

Scanned September 12, 2026

npx -y skills add baekenough/second-brain --skill jinja2-prompts --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Jinja2 Prompts?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Jinja2 Prompts
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/baekenough-jinja2-prompts/badge)](https://www.skillsdirectory.com/skills/baekenough-jinja2-prompts)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: jinja2-prompts
description: Parameterized prompt templates using Jinja2 patterns for reusable, dynamic agent prompts
scope: core
user-invocable: false
---

# Jinja2 Prompt Templates

## Purpose

Define reusable, parameterized prompt templates for agent tasks. Templates enable consistent prompt formatting across workflows while allowing dynamic content injection.

## Template Syntax

Use Jinja2-style variable interpolation in prompt strings:

```
{{ variable }}                        — Variable substitution
{% if condition %}...{% endif %}      — Conditional sections
{% for item in list %}...{% endfor %} — Iteration
{{ variable | default("fallback") }}  — Default values
```

## Security Rules

- Templates MUST be author-written (stored in skill files), never user-supplied
- Use `SandboxedEnvironment` (NOT `Environment` or `from_string()` directly)
- No access to `env()`, `os`, `subprocess`, or any system functions
- Variable allowlist: only explicitly provided context variables are accessible
- NEVER render user-controlled strings as templates — treat them as plain data

## Template Locations

```
.claude/skills/<skill-name>/templates/
  ├── analysis.md.j2
  ├── report.md.j2
  └── triage.md.j2
```

## Usage Pattern

```yaml
# In skill or workflow definition
template: analysis.md.j2
variables:
  target: "{{ repository_url }}"
  scope: "security"
  depth: "comprehensive"
```

Rendered by orchestrator before passing to agent as prompt.

## Common Templates

### Research Team Prompt

```
Role: {{ domain }} {{ role }} analyst
Scope: {{ topic }}

Tasks:
{% for task in tasks %}
{{ loop.index }}. {{ task }}
{% endfor %}

Output format:
{{ output_format }}
```

### CVE Triage Prompt

```
Analyze {{ cve_id }} ({{ cwe_classification }})
Affected component: {{ component }} {{ version_range }}
{% if existing_mitigations %}
Known mitigations: {{ existing_mitigations }}
{% endif %}
```

## Integration

- Used by `/research` skill for team prompt generation
- Used by `cve-triage` skill for standardized analysis prompts
- Compatible with DAG orchestration node prompts

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…