fastapi-expert

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides instructions for building web applications that ingest untrusted user input through API endpoints and Pydantic models.\n
  • Ingestion points: Request bodies (e.g., UserCreate in app/api/v1/endpoints/users.py) and query parameters (e.g., SearchQuery in section 5.2).\n
  • Boundary markers: The skill mandates the use of Pydantic v2 validation and strict type hinting to define data boundaries.\n
  • Capability inventory: The suggested patterns include database writes (SQLAlchemy), file system interactions for logging/streaming (aiofiles), and background task execution (arq).\n
  • Sanitization: The instructions explicitly require input sanitization via field_validator, parameterized queries via ORM to prevent SQL injection, and the exclusion of sensitive data from logs and responses.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 05:57 PM
Security Audit — agent-trust-hub — fastapi-expert