
jinja2
โ Officialโ 2,433by microsoft ยท part of microsoft/debugpy
Best practices for template rendering with Jinja2 including environments, filters, autoescaping, and security.
๐ฅ๐ฅ๐ฅ๐ฅโ VerifiedFreeQuick setup
๐งฐ Not standalone. This skill ships with microsoft/debugpy and only works together with that tool โ install the tool first, then add this skill.
This is the playbook your agent receives when the skill activates โ you don't need to read it to use the skill, but it's here to audit before installing.
Skill: Jinja2
Best practices for template rendering with Jinja2 including environments, filters, autoescaping, and security.
When to Use
Apply this skill when rendering templates with Jinja2 โ HTML pages, emails, configuration files, and code generation.
Environment
- Create a
jinja2.Environment(loader=..., autoescape=...)once and reuse it. - Use
FileSystemLoaderfor file-based templates,PackageLoaderfor installed packages. - Enable
autoescape=Truefor HTML templates to prevent XSS.
Templates
- Use
{{ variable }}for output,{% if/for/block %}for control flow. - Use template inheritance (
{% extends 'base.html' %}) for layout reuse. - Define custom filters for reusable transformations.
Security
- Always enable
autoescape=Truewhen rendering HTML. - Use
SandboxedEnvironmentfor untrusted templates. - Never render user input as template code โ only as template data.
- Use
|efilter explicitly when autoescape is off.
Pitfalls
- Don't use
Template(string)directly โ it bypasses the environment's loader and settings. - Watch for undefined variable errors โ use
undefined=StrictUndefinedduring development. - Avoid complex logic in templates โ keep them focused on presentation.
Copy & paste โ that's it
npx skills add microsoft/debugpy --skill "jinja2" --full-depthRun this in your project โ your agent picks the skill up automatically.
No common issues documented yet. If you hit a problem, the repository's GitHub Issues page is the best place to look.