fastapi-service-scaffold

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFE
Full Analysis
  • [SECURITY_BY_DESIGN]: The skill mandates a 'Secure by Default' posture. It explicitly prohibits hardcoding secrets in source code, committed configurations, or container images, and requires fail-fast validation for environment-injected settings.
  • [CONTAINER_SECURITY]: Generated Dockerfiles utilize multi-stage builds to minimize attack surface, run as non-root users, and use digest-pinned base images to ensure supply chain integrity.
  • [DEPENDENCY_MANAGEMENT]: The instructions require exact version pinning with hashed lockfiles (e.g., uv.lock) to prevent dependency confusion and ensure reproducible, tamper-evident builds.
  • [VERIFICATION_WORKFLOW]: Includes mandatory build verification steps, requiring successful execution of static analysis tools (mypy, ruff), unit tests (pytest), and a runtime smoke check (healthz probe) before the task is considered complete.
  • [INDIRECT_PROMPT_INJECTION]: While the skill ingests external data (backend-architecture.md), it follows strict output contracts and boundary markers, significantly mitigating the risk of instructions embedded in the architecture documentation influencing the agent's behavior beyond the intended scaffolding scope.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 08:35 AM
Security Audit — agent-trust-hub — fastapi-service-scaffold