Jinja2 技能创建
- 作者仓库星标 2,412
- 许可证 NOASSERTION
- 作者仓库 debugpy
Skill: Jinja2
Best practices for template rendering with Jinja2 including environments, filters, autoescaping, and security.
When to Use
Apply this skill when rendering templates with Jinja2 — HTML pages, emails, configuration files, and code generation.
Environment
- Create a
jinja2.Environment(loader=..., autoescape=...)once and reuse it. - Use
FileSystemLoaderfor file-based templates,PackageLoaderfor installed packages. - Enable
autoescape=Truefor HTML templates to prevent XSS.
Templates
- Use
{{ variable }}for output,{% if/for/block %}for control flow. - Use template inheritance (
{% extends 'base.html' %}) for layout reuse. - Define custom filters for reusable transformations.
Security
- Always enable
autoescape=Truewhen rendering HTML. - Use
SandboxedEnvironmentfor untrusted templates. - Never render user input as template code — only as template data.
- Use
|efilter explicitly when autoescape is off.
Pitfalls
- Don't use
Template(string)directly — it bypasses the environment's loader and settings. - Watch for undefined variable errors — use
undefined=StrictUndefinedduring development. - Avoid complex logic in templates — keep them focused on presentation.
- 流狐分类
- 通用
- 作者声明 Agent
- 未找到明确声明;不据此推断已兼容或已测试
- 静态检查
- 94 / 100 · 启发式扫描,不代表运行安全
- 作者 / 版本 / 许可
- @microsoft · NOASSERTION
- 流狐 Token 估算
- 低消耗
- 流狐接入估算
- 即装即用
- 是否需要外部 API Key
- 未发现要求
- 检测到的系统要求
- 未声明
- 底层运行要求
- 未声明
- 检测到的文件与系统行为
-
- 只读
- 允许写入 / 修改
- 检测到的网络行为
- 仅限本地
- 安装命令数
- 无(仅作为资料)
档案由构建时根据 SKILL.md 与安装命令自动衍生,可能与作者实际意图存在差异。
需要注意: 未限定 allowed-tools,默认拥有全部工具权限。
作者没有在当前 SKILL.md 中定义固定输出样例。 Apply this skill when rendering templates with Jinja2 — HTML pages, emails, configuration files, and code generation.
Create a jinja2.Environment(loader=..., autoescape=...) once and reuse it. Use FileSystemLoader for file-based templates, PackageLoader for installed packages. Enable autoescape=True for HTML templates to prevent XSS.
Use {{ variable }} for output, {% if/for/block %} for control flow. Use template inheritance ({% extends 'base.html' %}) for layout reuse. Define custom filters for reusable transformations.
Always enable autoescape=True when rendering HTML. Use SandboxedEnvironment for untrusted templates. Never render user input as template code — only as template data.
Don't use Template(string) directly — it bypasses the environment's loader and settings. Watch for undefined variable errors — use undefined=StrictUndefined during development. Avoid complex logic in templates — keep them focused on presentation.
# Skill: Jinja2
Best practices for template rendering with Jinja2 including environments, filters, autoescaping, and security.
## When to Use
Apply this skill when rendering templates with Jinja2 — HTML pages, emails, configuration files, and code generation.
## Environment
- Create a `jinja2.Environment(loader=..., autoescape=...)` once and reuse it.
- Use `FileSystemLoader` for file-based templates, `PackageLoader` for installed packages.
- Enable `autoescape=True` for HTML templates to prevent XSS.
## Templates
- Use `{{ variable }}` for output, `{% if/for/block %}` for control flow.
- Use template inheritance (`{% extends 'base.html' %}`) for layout reuse.
- Define custom filters for reusable transformations.
## Security
- **Always** enable `autoescape=True` when rendering HTML.
- Use `SandboxedEnvironment` for untrusted templates.
- Never render user input as template code — only as template data.
- Use `|e` filter explicitly when autoescape is off.
## Pitfalls
- Don't use `Template(string)` directly — it bypasses the environment's loader and settings.
- Watch for undefined variable errors — use `undefined=StrictUndefined` during development.
- Avoid complex logic in templates — keep them focused on presentation. 作者原文负责流程事实;流狐只索引当前章节、要点、文件与命令。
章节 -> When to Use → Environment → Templates → Security → Pitfalls
要点 -> Always · Best practices for template rendering with Jinja2 including environments, filters, autoescaping, and security. · Apply this skill when rendering templates with Jinja2 — HTML pages, emails, configuration files, and code generation. · - Create a jinja2.Environment(loader=..., autoescape=...) once and reuse it. · - Use {{ variable }} for output, {% if/for/block %} for control flow. · - Always enable autoescape=True when rendering HTML. · - Don't use Template(string) directly — it bypasses the environment's loader and settings.
文件/命令 -> jinja2.Environment(loader=..., autoescape=...) · FileSystemLoader · PackageLoader · autoescape=True · {{ variable }} · {% if/for/block %} · {% extends 'base.html' %} · SandboxedEnvironment
内容 SHA-256 -> 3ace875bcc67
原文结构
适用与边界
原文中的明确线索
jinja2.Environment(loader=..., autoescape=...)、FileSystemLoader、PackageLoader、autoescape=True、{{ variable }}、{% if/for/block %}、{% extends 'base.html' %}、SandboxedEnvironment