Home / steph-dove / klaussy-agents · examples/fastapi/.agents/skills/fastapi-security-audit/SKILL.md · GitHub

fastapi-security-audit skillA

fastapi-security-audit is agent-read markdown (skill) from steph-dove/klaussy-agents: Use when the user wants a focused security pass over the current change — scanning the branch diff for leaked secrets, injection and SSRF, broken access control, unsafe deserialization, and newly added or vulnerable dependencies. Narrower and deeper than the general review skill: it applies only the security lenses and reports findings; it does not refactor or fix. Also known as `klaussy-security-audit`..

Indexed from public GitHub and served as immutable, content-addressed versions. Install it pinned to an exact SHA-256 with the mdr CLI, and every file is verified against the hash recorded here before it reaches your agent. The deterministic audit below grades the latest version, and the same file always earns the same grade.

What the file says

You are running a security audit of the current change. Scope is the diff against the base branch and the immediate context of what it touches — not the whole tree, and not style or architecture. Report findings only; do not edit code.

If `master` is missing or unset, default to `dev` if it exists, otherwise `main`. Read the change with `git diff master...HEAD` first.

## Lenses

Apply each lens to the ADDED and changed lines. A finding must point to a concrete line, not a general worry.

**1. Secrets & credentials** (Severity: High)
- API keys, tokens, passwords, private keys, connection strings with embedded credentials, or high-entropy literals that look like real secrets in added lines. Obvious placeholders (`YOUR_API_KEY`, `xxx`, `changeme`) are not findings.

**2. Injection & untrusted input** (Severity: High)
- SQL/NoSQL built by string concatenation or f-strings from request input instead of parameterized queries.
- Shell execution from untrusted input (`shell=True`, string-built commands, `eval`/`exec`).
- Command, path-traversal, template, or header injection where user input reaches a sink unsanitized.

**3. SSRF & outbound requests** (Severity: High)
…

Read the whole file at its exact version.

How to install

Latest version
mdr add steph-dove/klaussy-agents/fastapi-security-audit@git:20260922.549c04f
Exact content
mdr add steph-dove/klaussy-agents/fastapi-security-audit@sha256:a390278a2a1841ef

Pin to a label to follow the author's releases, or to a sha256 to freeze the exact bytes forever. Either way the resolved hash is written to mdr.lock, and mdr install reproduces it on any machine.

Badge

mdr badge

[![mdr](https://markdownregistry.com/badge/art_sqtyc3cpthvo42yt.svg)](https://markdownregistry.com/a/art_sqtyc3cpthvo42yt)

1 badge views in 30 days

Versions

versioncommittedcommitsizeaudit
git:20260922.549c04f latest2026-09-22 549c04f 4,037 BA view · diff
git:20260918.4ac79242026-09-18 4ac7924 14,769 BA view · diff
git:20260918.e529a802026-09-18 e529a80 14,729 BA view · diff
git:20260716.30d2fb12026-07-16 30d2fb1 8,312 BA view · diff
git:20260630.a387a0a2026-06-30 a387a0a 6,266 BA view

Audit of the latest version

A  17 of 17 checks passed. Deterministic, no model, same answer every run.
  • pass: Frontmatter block present
  • pass: Frontmatter declares a name
  • pass: Frontmatter declares a description
  • pass: Size between 200 bytes and 200 KB (4037 bytes)
  • pass: No zero-width or bidi control characters
  • pass: No instruction hidden inside an HTML comment
  • pass: No link to an exfiltration or paste host
  • pass: No credential-shaped string
  • pass: No instruction to send local credentials anywhere
  • pass: No text hidden with inline styles
  • pass: No prompt-injection phrasing
  • pass: No curl or wget piped into a shell
  • pass: No recursive delete of root, home or parent
  • pass: No instruction to read or print local credentials
  • pass: No base64 blob over 200 characters
  • pass: No link to a raw IP address
  • pass: No script tag

Source

GitHub

steph-dove/klaussy-agents · 16 stars · license MIT · pushed 2026-09-24 · branch main

API

GET https://markdownregistry.com/api/v1/artifacts/art_sqtyc3cpthvo42yt
GET https://markdownregistry.com/api/v1/resolve?ref=steph-dove/klaussy-agents/fastapi-security-audit
GET https://markdownregistry.com/api/v1/blob/a390278a2a1841efc8d1552b7cf6a421b4a879bc14648fc2dc5f9d2699355d1c

Your agent does the legwork. You hear about the deals worth your word. Hand yours the standing instructions at modelranch.com and it joins the network that reads files like this one.

More from steph-dove/klaussy-agents

fastapi-address-review skill
steph-dove/klaussy-agents · examples/fastapi/.agents/skills/fastapi-address-review/SKILL.md · Use when a PR has review feedback and the user wants it addressed — pull the review comments, triage each one, apply…
git:20260922.549c04f · audit A · 16 stars
fastapi-adr-generator skill
steph-dove/klaussy-agents · examples/fastapi/.agents/skills/fastapi-adr-generator/SKILL.md · Use when the user wants to record an architectural decision — drafting an Architecture Decision Record (ADR) or RFC…
git:20260922.549c04f · audit A · 16 stars
fastapi-commit skill
steph-dove/klaussy-agents · examples/fastapi/.agents/skills/fastapi-commit/SKILL.md · Use when the user wants a commit message written for currently staged changes. Reads `git diff --cached`, recent log…
git:20260922.549c04f · audit A · 16 stars
fastapi-debug skill
steph-dove/klaussy-agents · examples/fastapi/.agents/skills/fastapi-debug/SKILL.md · Use when the user reports an error, bug, or unexpected behavior in this repo and wants help diagnosing it. Five phases…
git:20260918.4ac7924 · audit A · 16 stars
fastapi-deps skill
steph-dove/klaussy-agents · examples/fastapi/.agents/skills/fastapi-deps/SKILL.md · Use when the user wants to upgrade the project's dependencies safely — bump versions, read changelogs for breaking…
git:20260922.549c04f · audit A · 16 stars
fastapi-document skill
steph-dove/klaussy-agents · examples/fastapi/.agents/skills/fastapi-document/SKILL.md · Use when the user wants documentation written or updated — docstrings, API docs, a README section, or a doc comment on…
git:20260922.549c04f · audit A · 16 stars
fastapi-explain skill
steph-dove/klaussy-agents · examples/fastapi/.agents/skills/fastapi-explain/SKILL.md · Use when the user wants code, a concept, or the current diff explained in this repo. With no specific target, explains…
git:20260922.549c04f · audit A · 16 stars
fastapi-fix skill
steph-dove/klaussy-agents · examples/fastapi/.agents/skills/fastapi-fix/SKILL.md · Use when the user wants lint, format, and type errors fixed in the current changes. Reads CLAUDE.md for the repo's…
git:20260918.4ac7924 · audit A · 16 stars
fastapi-grant-permissions skill
steph-dove/klaussy-agents · examples/fastapi/.agents/skills/fastapi-grant-permissions/SKILL.md · Use when the user is tired of approving the same routine dev work ("stop asking me yes", "allow the normal dev tools"…
git:20260918.4ac7924 · audit B · 16 stars
fastapi-humanize skill
steph-dove/klaussy-agents · examples/fastapi/.agents/skills/fastapi-humanize/SKILL.md · Use whenever prose, a comment, a doc, a PR or commit body, or a file's text should read like a human engineer wrote it…
git:20260922.549c04f · audit A · 16 stars
fastapi-implement skill
steph-dove/klaussy-agents · examples/fastapi/.agents/skills/fastapi-implement/SKILL.md · Use when the user pastes a ticket, design doc, or task description and wants it implemented. Multi-phase flow —…
git:20260918.4ac7924 · audit A · 16 stars
fastapi-new-worktree skill
steph-dove/klaussy-agents · examples/fastapi/.agents/skills/fastapi-new-worktree/SKILL.md · Use when the user wants a new git worktree created for a task. Picks a kebab-case branch name with a…
git:20260922.549c04f · audit A · 16 stars

Every file in steph-dove/klaussy-agents

Browse by kind, by grade A, or by owner.