production-fast-api-template
Pass
Audited by Gen Agent Trust Hub on Oct 7, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The analyzed skill consists of documentation and standard definitions for a project template. No malicious scripts, obfuscated payloads, or unauthorized network operations were detected.
- [PROMPT_INJECTION]: The static analysis flag regarding prompt injection is a false positive. The skill contains documentation (in
AGENT_SECURITY.mdandGUARDRAILS.md) that defines prompt injection and instruction-ignoring attacks to explain how a developer should build defenses against them. The skill does not contain instructions that attempt to override the AI's core safety guidelines or system prompt. - [COMMAND_EXECUTION]: The skill documentation provides strict standards for command execution, specifically recommending against the use of shell execution (
shell=False) and mandating isolated sandboxes for any agentic code execution. No active command execution occurs within the skill itself. - [CREDENTIALS_SAFE]: The skill prescribes secure secret management practices, including the use of Pydantic's
SecretStrand environment-injected secrets (AWS Secrets Manager/SSM), and explicitly forbids hardcoding credentials in code, logs, or prompts. - [INDIRECT_PROMPT_INJECTION]: While the skill defines a framework that handles untrusted data (RAG and Agent tools), it includes a robust defense-in-depth model requiring multi-layered validation and content-safety guardrails (G1-G6) to mitigate injection risks. As a documentation-only skill, it does not possess an active attack surface.
Audit Metadata