Fastapi Attack Probe

Authorized self-pentest probe targeting FastAPI-specific weaknesses. Tests /docs and /redoc auth, OpenAPI schema enumeration, Pydantic boundary bypass via extra fields, missing Depends/Security on routes, JWT alg confusion, and unsafe file responses. Use when the user asks to "pentest" their own FastAPI app.

Dolphinllc 73fd3e3 5.5 KB Updated

File contents

Dolphinllc/claude-security-skills/tree/main/skills/offensive/web/fastapi-attack-probe commit 73fd3e3cdb

Frequently asked questions

npx skillmds@latest add dolphinllc/fastapi-attack-probe