fastapi-expert

Fail

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: CRITICALEXTERNAL_DOWNLOADSMETADATA_POISONING
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The documentation URL https://jeffallan.github.io/claude-skills/skills/backend/fastapi-expert/ and its non-HTTPS variant are explicitly blacklisted by security scanners (URL:Blacklist). Interaction with this domain represents a high risk of exposure to malicious content or phishing.
  • [METADATA_POISONING]: The skill's primary file SKILL.md has been identified as malicious by file reputation scanners (FileRepMalware). The metadata fields, including the author and documentation links, point to external resources with confirmed malicious associations.
  • [REMOTE_CODE_EXECUTION]: While no direct shell execution (e.g., curl | bash) is present, the instruction to 'verify OpenAPI docs at /docs' or load documentation from a blacklisted site could be used as a vector to deliver malicious payloads to the user or agent environment.
Recommendations
  • CRITICAL: 1 file(s) identified as malware by FileRep - DO NOT USE
  • AI detected serious security threats
  • Contains 2 malicious URL(s) - DO NOT USE
Audit Metadata
Risk Level
CRITICAL
Analyzed
Sep 6, 2026, 11:35 AM
Security Audit — agent-trust-hub — fastapi-expert