fastapi-development
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The file upload demonstration in
EXAMPLES.mdcontains a directory traversal vulnerability due to unsafe handling of user-supplied filenames. - Ingestion points: The
upload_fileandupload_multiple_filesendpoints inEXAMPLES.mdacceptUploadFileobjects containing user-controlled filenames. - Boundary markers: The instructions do not include boundary markers or warnings advising the user to sanitize or ignore instructions embedded within external file metadata.
- Capability inventory: The skill includes file system write capabilities via
shutil.copyfileobjand directory operations inEXAMPLES.md. - Sanitization: The code lacks sanitization for the
file.filenameattribute; it directly concatenates this untrusted string to theUPLOAD_DIRpath (UPLOAD_DIR / file.filename). This allows a malicious actor to provide a filename containing traversal sequences (e.g.,../../etc/passwd) to write files to arbitrary locations on the server.
Audit Metadata