fastapi-microservices-development

Warn

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: In EXAMPLES.md, the Redis Caching Layer section provides code that uses the pickle module for serializing and deserializing cached data. The use of pickle.loads(value) on data retrieved from the cache is an unsafe deserialization pattern. If an attacker manages to modify the data in the Redis instance, they could achieve arbitrary code execution on the application server.
  • [INDIRECT_PROMPT_INJECTION]: The skill describes multiple ingestion points for external data, creating an attack surface for indirect prompt injection.
  • Ingestion points: REST API endpoints (e.g., create_user in auth.py, upload_file in file_upload.py) and WebSocket connections (e.g., websocket_chat.py) handle user-provided payloads and files.
  • Boundary markers: The skill extensively uses Pydantic schemas (UserCreate, ItemCreate) as boundary markers to validate input types and structures.
  • Capability inventory: The skill possesses capabilities for database operations (SQLAlchemy, Motor), file system modifications (aiofiles), and outbound network requests (httpx).
  • Sanitization: While type validation is enforced by Pydantic, the skill relies on developers to implement further sanitization against malicious instructions embedded in strings.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 15, 2026, 09:22 AM
Security Audit — agent-trust-hub — fastapi-microservices-development