fastapi-templates
Audited by ZeroLeaks on Apr 15, 2026
**Executive Summary** SKILL.md is mostly clear, though one transparency concern around a potential hardcoded credential weakens reviewability and warrants a closer look before production use. The skill keeps instruction and data boundaries reasonably separate and does not push the agent to treat external content as trusted instructions. Behavior analysis was not run, which, combined with the credential concern, limits confidence — the scan passed, but the narrow validation scope means this is a low-confidence result and finite testing cannot guarantee safety across all scenarios.
The skill has 1 transparency concern that weaken pre-use reviewability, mainly around potential hardcoded credential.
The scanned skill keeps data and instructions reasonably separate and does not strongly encourage the agent to treat external content as policy.
Behavior analysis was not run.
Potential hardcoded credential