fastapi-expert

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides comprehensive templates for FastAPI development, including secure JWT authentication and async database operations. It correctly emphasizes using environment variables for sensitive configuration and implements password hashing using standard libraries like passlib and bcrypt.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied requirements to generate application code and database schemas, which is a standard operational surface for indirect prompt injection. 1. Ingestion points: The agent ingests user specifications for API endpoints and data models through the workflow defined in SKILL.md. 2. Boundary markers: The skill leverages Pydantic V2 schemas for structural validation of data, although it does not define specific prompt-level delimiters to isolate user input from architectural instructions. 3. Capability inventory: The skill empowers the agent to generate Python source code, define database migrations, and configure authentication logic, as demonstrated in references/async-sqlalchemy.md and references/authentication.md. 4. Sanitization: Input validation is handled by Pydantic's type-safety and validation features, providing robust data-level sanitization.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:50 PM
Security Audit — agent-trust-hub — fastapi-expert