fastapi-security-scan
Pass
Audited by Gen Agent Trust Hub on May 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides a structured set of rules and code examples for auditing FastAPI projects. It functions as a technical guide for an AI agent to perform code reviews and does not contain instructions that bypass safety filters or override behavior.
- [SAFE]: No obfuscation, data exfiltration, or persistence mechanisms were detected. The content consists of plain-text markdown and standard Python code snippets used for educational purposes.
- [SAFE]: External references point to well-known and trusted sources, including the official FastAPI documentation, PyJWT documentation, and the OWASP API Security project. These are used to provide legitimate technical context for the scanning rules.
- [SAFE]: The skill does not involve dynamic execution, privilege escalation, or remote code downloads. While it discusses potentially dangerous packages (like
passliborargon2-cffi), it does so in the context of recommending secure best practices for password hashing.
Audit Metadata