Agent Skills
› microsoft/debugpy
› jinja2
jinja2
GitHub提供 Jinja2 模板渲染的最佳实践,涵盖环境配置、过滤器使用、模板继承及安全防护(如自动转义和沙箱环境),适用于 HTML、邮件及代码生成等场景。
触发场景
使用 Jinja2 渲染 HTML 页面或邮件
需要生成配置文件或代码
处理模板安全与 XSS 防护
安装
npx skills add microsoft/debugpy --skill jinja2 -g -y
SKILL.md
Frontmatter
{
"name": "jinja2",
"description": "Best practices for template rendering with Jinja2 including environments, filters, autoescaping, and security."
}
Skill: Jinja2
Best practices for template rendering with Jinja2 including environments, filters, autoescaping, and security.
When to Use
Apply this skill when rendering templates with Jinja2 — HTML pages, emails, configuration files, and code generation.
Environment
- Create a
jinja2.Environment(loader=..., autoescape=...)once and reuse it. - Use
FileSystemLoaderfor file-based templates,PackageLoaderfor installed packages. - Enable
autoescape=Truefor HTML templates to prevent XSS.
Templates
- Use
{{ variable }}for output,{% if/for/block %}for control flow. - Use template inheritance (
{% extends 'base.html' %}) for layout reuse. - Define custom filters for reusable transformations.
Security
- Always enable
autoescape=Truewhen rendering HTML. - Use
SandboxedEnvironmentfor untrusted templates. - Never render user input as template code — only as template data.
- Use
|efilter explicitly when autoescape is off.
Pitfalls
- Don't use
Template(string)directly — it bypasses the environment's loader and settings. - Watch for undefined variable errors — use
undefined=StrictUndefinedduring development. - Avoid complex logic in templates — keep them focused on presentation.
版本历史
- e5743d3 当前 2026-08-20 17:01


