fastapi-expert
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides instructions for building web applications that ingest untrusted user input through API endpoints and Pydantic models.\n
- Ingestion points: Request bodies (e.g.,
UserCreateinapp/api/v1/endpoints/users.py) and query parameters (e.g.,SearchQueryin section 5.2).\n - Boundary markers: The skill mandates the use of Pydantic v2 validation and strict type hinting to define data boundaries.\n
- Capability inventory: The suggested patterns include database writes (SQLAlchemy), file system interactions for logging/streaming (
aiofiles), and background task execution (arq).\n - Sanitization: The instructions explicitly require input sanitization via
field_validator, parameterized queries via ORM to prevent SQL injection, and the exclusion of sensitive data from logs and responses.
Audit Metadata