fastapi-service-scaffold
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFE
Full Analysis
- [SECURITY_BY_DESIGN]: The skill mandates a 'Secure by Default' posture. It explicitly prohibits hardcoding secrets in source code, committed configurations, or container images, and requires fail-fast validation for environment-injected settings.
- [CONTAINER_SECURITY]: Generated Dockerfiles utilize multi-stage builds to minimize attack surface, run as non-root users, and use digest-pinned base images to ensure supply chain integrity.
- [DEPENDENCY_MANAGEMENT]: The instructions require exact version pinning with hashed lockfiles (e.g., uv.lock) to prevent dependency confusion and ensure reproducible, tamper-evident builds.
- [VERIFICATION_WORKFLOW]: Includes mandatory build verification steps, requiring successful execution of static analysis tools (mypy, ruff), unit tests (pytest), and a runtime smoke check (healthz probe) before the task is considered complete.
- [INDIRECT_PROMPT_INJECTION]: While the skill ingests external data (backend-architecture.md), it follows strict output contracts and boundary markers, significantly mitigating the risk of instructions embedded in the architecture documentation influencing the agent's behavior beyond the intended scaffolding scope.
Audit Metadata