Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIMuseMuseDotsDots+22 more

    FastAPIGuard: Security & Async Boundary Validator

    1

    Security and performance guardrails for FastAPI to prevent JWT exploits, IDOR, and event-loop blocking.

    $19

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    Security scanned
    FastAPIGuard: Security & Async Boundary Validator

    FastAPIGuard: Security & Async Boundary Validator

    Example session with this skill installed

    Audit my FastAPI endpoint for security risks:

    @app.get("/orders/{order_id}")
    async def get_order(order_id: int, user = Depends(get_user)):
        return db.query("SELECT * FROM orders WHERE id = ?", order_id)
    
    • Read your context and instructions
    • Compiled the fastapiguard
    • Generated the document

    I have audited the code for security and async violations. Three critical issues were identified that could lead to data leakage and server stalls.

    FastAPI Security Audit

    ViolationTypeDetailAction Required
    ERR_ASYNC_EVENT_LOOP_BLOCKCRITICALSync db.query inside async def blocks the event loop.Change async def to def or use an async driver.
    ERR_IDOR_RISKCRITICALEndpoint returns order data without verifying user.id owns order_id.Add ownership check: if order.user_id != user.id.
    ERR_ENUMERATIONWARNINGStandard 403 response for unauthorized access leaks resource existence.Return 404 for unauthorized access to prevent ID guessing.

    Remediation Code

    from fastapi import HTTPException, Depends
    
    @app.get("/orders/{order_id}")
    def get_order(order_id: int, user = Depends(get_user)):
        # Running as 'def' moves sync DB call to FastAPI's threadpool
        order = db.query("SELECT * FROM orders WHERE id = ?", order_id).first()
        
        # Protect against IDOR and Enumeration
        if not order or order.user_id != user.id:
            raise HTTPException(status_code=404, detail="Order not found")
            
        return order
    

    Next steps

    1. Replace the existing async endpoint with the provided synchronous handler to protect the event loop.
    2. Verify that your get_user dependency is pinning its JWT decoding algorithm.
    3. Run a full project scan to ensure /docs is disabled in your production environment variable settings.

    fastapiguard-security-async-boundary-val.pdf

    PDF · document

    Generated

    Example file from a real run - the skill writes it into your workspace.

    Connects securely to your tools. The creator never sees your data.

    What you get

    Prevent JWT algorithm confusion exploits in auth dependencies.Detect synchronous blocking calls that stall the FastAPI event loop.Flag IDOR vulnerabilities where user ownership is not verified.Audit FastAPI configuration to hide OpenAPI docs in production.

    About this skill

    AI agents frequently write FastAPI code that looks correct but fails under load or attack. They often forget to pin JWT algorithms, accidentally block the event loop with synchronous calls, or leave internal documentation exposed in production. This skill acts as a security and performance gatekeeper for Python backends.

    What it does

    • JWT Guard — Prevents algorithm confusion by enforcing explicit algorithms allowlists in jwt.decode calls.
    • Async Boundary Check — Detects event-loop blocking calls like requests, time.sleep, or sync DB drivers inside async def handlers.
    • IDOR Protection — Flags endpoints that return resources without verifying the authenticated user's ownership.
    • Schema Hardening — Identifies exposed /docs or /openapi.json routes in production configurations.
    • Privacy Enforcement — Scans for and blocks the processing of files containing hardcoded secrets or API keys.

    How it works

    1. Analyze — Trigger the skill when an agent proposes a new FastAPI route, authentication dependency, or database integration.
    2. Audit — The skill scans the proposed or existing code against five core security and performance modules.
    3. Report — It returns a structured JSON audit report identifying specific violations like ERR_JWT_ALGORITHM_CONFUSION or ERR_IDOR_RISK.
    4. Remediate — The skill provides the specific code changes required to pin algorithms, move sync code to threadpools, or add ownership checks.

    Frameworks & tools

    Specifically designed for FastAPI projects using Python-jose or PyJWT for authentication. It targets common pitfalls with SQLAlchemy, Tortoise ORM, and standard synchronous libraries like requests.

    Why this beats prompting it yourself

    Generic prompts often miss the subtle difference between a sync and async FastAPI handler, leading to production performance degradation. This skill encodes specific OWASP API security patterns and Starlette-specific event loop rules that standard LLMs frequently ignore.

    Use cases

    • Auditing new authentication dependencies for JWT vulnerabilities.
    • Converting legacy synchronous code to async without stalling the event loop.
    • Reviewing FastAPI app configurations before a production deployment.
    • Ensuring multi-tenant data isolation by catching missing ownership checks.

    Known limitations

    Does not support non-FastAPI frameworks like Flask or Django. Projects using third-party managed auth providers like Clerk or Auth0 are outside the scope of the JWT validator.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean today

    • Passed all security checks, Safe to install

    Needs access to

    Tiangolo

    Listedtoday

    What's inside

    Frequently Asked Questions