Fix Slow Endpoint
vpcarlos/profyle
Diagnose and fix a slow endpoint or request in a Python web app (FastAPI, Flask, Django, Tornado, any ASGI/WSGI framework) using real Profyle/VizTracer traces, then prove the fix by replaying the…
Run defensive pre-release security tests for Python web applications.
$ npx skills add aiskillstore/marketplace --skill python-web-app-security-audit -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install aiskillstore/marketplace python-web-app-security-audit --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/aiskillstore/marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/glenskii/python-web-app-security-audit .claude/skills/python-web-app-security-audit && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "python-web-app-security-audit" agent skill from https://github.com/aiskillstore/marketplace/tree/main/skills/glenskii/python-web-app-security-audit into .claude/skills/python-web-app-security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "python-web-app-security-audit", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/aiskillstore/marketplace/tree/main/skills/glenskii/python-web-app-security-auditType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add aiskillstore/marketplace --skill python-web-app-security-audit -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install aiskillstore/marketplace python-web-app-security-audit --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aiskillstore/marketplace.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/glenskii/python-web-app-security-audit .agents/skills/python-web-app-security-audit && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "python-web-app-security-audit" agent skill from https://github.com/aiskillstore/marketplace/tree/main/skills/glenskii/python-web-app-security-audit into .agents/skills/python-web-app-security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "python-web-app-security-audit", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aiskillstore/marketplace --skill python-web-app-security-audit -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install aiskillstore/marketplace python-web-app-security-audit --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aiskillstore/marketplace.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/glenskii/python-web-app-security-audit .cursor/skills/python-web-app-security-audit && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "python-web-app-security-audit" agent skill from https://github.com/aiskillstore/marketplace/tree/main/skills/glenskii/python-web-app-security-audit into .cursor/skills/python-web-app-security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "python-web-app-security-audit", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/aiskillstore/marketplace.git --path skills/glenskii/python-web-app-security-audit--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add aiskillstore/marketplace --skill python-web-app-security-audit -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install aiskillstore/marketplace python-web-app-security-audit --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aiskillstore/marketplace.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/glenskii/python-web-app-security-audit .gemini/skills/python-web-app-security-audit && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "python-web-app-security-audit" agent skill from https://github.com/aiskillstore/marketplace/tree/main/skills/glenskii/python-web-app-security-audit into .gemini/skills/python-web-app-security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "python-web-app-security-audit", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install aiskillstore/marketplace python-web-app-security-auditInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add aiskillstore/marketplace --skill python-web-app-security-audit -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/aiskillstore/marketplace.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/glenskii/python-web-app-security-audit .github/skills/python-web-app-security-audit && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "python-web-app-security-audit" agent skill from https://github.com/aiskillstore/marketplace/tree/main/skills/glenskii/python-web-app-security-audit into .github/skills/python-web-app-security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "python-web-app-security-audit", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add aiskillstore/marketplace --skill python-web-app-security-audit -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install aiskillstore/marketplace python-web-app-security-audit --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/aiskillstore/marketplace.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/glenskii/python-web-app-security-audit .opencode/skills/python-web-app-security-audit && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "python-web-app-security-audit" agent skill from https://github.com/aiskillstore/marketplace/tree/main/skills/glenskii/python-web-app-security-audit into .opencode/skills/python-web-app-security-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "python-web-app-security-audit", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
python-web-app-security-auditRun defensive pre-release security tests for Python web applications.
Python Web App Security Audit is an agent skill from aiskillstore/marketplace. Run defensive pre-release security tests for Python web applications. Use for FastAPI, Django, Flask, and ASGI services: the common interface between Python web apps and servers. Tests authentication, authorization, hostile input, headers, CORS, cookies, rate limits, errors, and configuration to return evidence-backed findings and clear test boundaries.
Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 32 other files, including scripts, reference files and assets (for example `README.md`, `agents/openai.yaml` and `assets/security-audit-report-template.md`).
It sits in Backend & APIs, covering Backend development, Security review and Rate limiting. It works with Python, Django, FastAPI and Flask. The repository describes itself as: Security-audited skills for Claude, Codex & Claude Code. One-click install, quality verified. The licence is MIT.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 4ac52da. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Python, from the files we listed), which the agent can run.
Shell commands in SKILL.md call:
pippythonpytestFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use pip, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Python Web App Security Audit loads about 1.2k tokens when it runs, and up to ~3k if it reads all its reference files. Until then it costs about 96 tokens; SKILL.md has 503 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
ty/`, `pytest.ini` when absent, and the `.env.test.template` file. It never creates a credentials file.the copied `security/` directory, copy `.env.test.template` to `.env.test`. Supply an app import path, routes, rate limAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from aiskillstore/marketplace at commit 4ac52da, republished under its MIT licence (© aiskillstore). 503 words, ~1,230 tokens.
.claude/skills/python-web-app-security-audit/SKILL.md (or your agent's skills folder). This skill also uses 27 other files; get the full folder from GitHub.Run a configurable pytest suite against a local Python web application before release. It uses ASGI, the interface between a Python web app and its server, so the checks can exercise FastAPI, Django, Flask through an adapter, and comparable services without opening a public server.
The bundled checks cover authentication, authorization, input validation, response headers, CORS, cookies, rate limits, error handling, HTTP method handling, and unsafe configuration. Read setup and boundaries, framework adapters, route configuration, fixture safety, and assertion catalog before adapting the suite to an application.
Do not represent a passing run as a penetration test or proof of production security. The suite does not verify deployment TLS, a WAF, dependency vulnerabilities, external infrastructure, or controls it cannot reach through the configured test application.
Install the dependencies in the target project's isolated environment.
pip install "pytest>=8" "pytest-asyncio>=0.24" "httpx>=0.27" python-dotenvCopy the bundled suite into the target project without overwriting an existing security directory.
python scripts/prepare_security_suite.py C:\path\to\your-projectThe helper copies security/, pytest.ini when absent, and the .env.test.template file. It never creates a credentials file.
In the copied security/ directory, copy .env.test.template to .env.test. Supply an app import path, routes, rate limit, permitted origin, and dedicated test credentials. Keep .env.test out of version control.
From the target project root, run the suite.
pytest security/ -vUse the report template, release decision guide, and continuous integration guide. For every finding, state the affected route or control, evidence, severity, recommended fix, and what was not tested. End with one of these release decisions:
| File | Purpose |
|---|---|
security/conftest.py | Application import, test client, authentication fixtures, and route helpers |
security/test_headers.py | Header presence and directive quality |
security/test_validation.py | Hostile input, malformed payloads, and type coercion |
security/test_auth.py | Authentication enforcement and enumeration resistance |
security/test_authorization.py | Object ownership, role boundaries, and mass assignment |
security/test_rate_limit.py | Threshold and 429 response checks |
security/test_errors.py | Error sanitization and internal detail leakage |
security/test_cors.py | Origin restrictions and preflight handling |
security/test_cookies.py | Cookie flag enforcement |
security/test_config.py | Debug exposure, method handling, and configuration checks |
This skill does not replace manual security assessment, dependency scanning, production HTTPS verification, WAF validation, or dynamic scanning. Add an application-specific CSRF test when state-changing requests use cookie authentication.
The bundled suite does not create accounts, delete records, or execute schema-changing database commands. Assess any registration or other write flow only in an application-owned test suite with a disposable database and explicit cleanup.
© aiskillstore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 27 other files (scripts, references, assets) in skills/glenskii/python-web-app-security-audit of aiskillstore/marketplace.
Open the folder on GitHubat commit 4ac52da
Python Web App Security Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Python Web App Security Audit this skillaiskillstore/marketplace | 430 | — | ~1.2k | Automated safety check: Notes | MIT | |
| Fix Slow Endpointvpcarlos/profyle | 123 | — | ~2.1k | Automated safety check: Pass | MIT | |
| Framework Migration AssistantArabelaTso/Skills-4-SE | 253 | — | ~1.9k | Automated safety check: Pass | Apache-2.0 | |
| Sentry Python SDKgetsentry/sentry-for-ai | 268 | — | ~4.1k | Automated safety check: Pass | Apache-2.0 | |
| Python Appservice Deploymicrosoft/GitHub-Copilot-for-Azure | 255 | 1 repos | ~688 | Automated safety check: Pass | MIT | |
| Python Devdoccker/cc-use-exp | 1.1k | — | ~790 | Automated safety check: Pass | Custom licence |
vpcarlos/profyle
Diagnose and fix a slow endpoint or request in a Python web app (FastAPI, Flask, Django, Tornado, any ASGI/WSGI framework) using real Profyle/VizTracer traces, then prove the fix by replaying the…
ArabelaTso/Skills-4-SE
Automatically migrate Python web applications between frameworks (Flask → FastAPI, Django → FastAPI).
getsentry/sentry-for-ai
Full Sentry SDK setup for Python. An agent skill from getsentry/sentry-for-ai.
microsoft/GitHub-Copilot-for-Azure
Deploy Python (Flask/Django/FastAPI) code to Azure App Service Linux.
doccker/cc-use-exp
Python 开发规范。当用户操作 .py、pyproject.toml、requirements.txt、setup.py 文件, 或涉及 FastAPI、Django、Flask、pytest、asyncio 开发时触发。
jh941213/my-cc-harness
Production-grade FastAPI project creation and setup guide. An agent skill from jh941213/my-cc-harness.
aiskillstore/marketplace
Analyze codebase with tokei (fast line counts by language) and difft (semantic AST-aware diffs).
aiskillstore/marketplace
Process JSON with jq and YAML/TOML with yq. An agent skill from aiskillstore/marketplace.
aiskillstore/marketplace
Scans for project documentation files (AGENTS.md, CLAUDE.md, GEMINI.md, COPILOT.md, CURSOR.md, WARP.md, and 15+ other formats) and synthesizes guidance.
aiskillstore/marketplace
Modern file and content search using fd, ripgrep (rg), and fzf.
aiskillstore/marketplace
Modern find-and-replace using sd (simpler than sed) and batch replacement patterns.
aiskillstore/marketplace
Automatically activated when user asks how something works, wants to understand unfamiliar code, needs to explore a new codebase, or asks questions like "where is X implemented?", "how does Y…
Categories
Run defensive pre-release security tests for Python web applications. Python Web App Security Audit is an agent skill from aiskillstore/marketplace. Run defensive pre-release security tests for Python web applications.
Python Web App Security Audit fits situations like: ASGI services: the common interface between Python web apps and servers; tasks that involve Backend development; tasks that involve Security review.
Run `npx skills add aiskillstore/marketplace --skill python-web-app-security-audit -a claude-code`. Or copy the skill folder (skills/glenskii/python-web-app-security-audit in aiskillstore/marketplace) into .claude/skills/python-web-app-security-audit in your project. Claude Code loads it when a task matches its description.
Run `npx skills add aiskillstore/marketplace --skill python-web-app-security-audit -a codex`. Or copy the skill folder (skills/glenskii/python-web-app-security-audit in aiskillstore/marketplace) into .agents/skills/python-web-app-security-audit in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aiskillstore/marketplace --skill python-web-app-security-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/python-web-app-security-audit, .gemini/skills/python-web-app-security-audit, .github/skills/python-web-app-security-audit and .opencode/skills/python-web-app-security-audit in your project.
Going by SKILL.md and its folder, Python Web App Security Audit needs Python for the scripts in its folder and the command-line tools its instructions call (pip, python and pytest). Our summary lists: Python 3.
SKILL.md contains no URLs. Its commands use pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Python Web App Security Audit is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.2k tokens (SKILL.md is roughly 4.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.7k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Python Web App Security Audit: Fix Slow Endpoint (vpcarlos/profyle, 123 stars), Framework Migration Assistant (ArabelaTso/Skills-4-SE, 253 stars), Sentry Python SDK (getsentry/sentry-for-ai, 268 stars) and Python Appservice Deploy (microsoft/GitHub-Copilot-for-Azure, 255 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
aiskillstore (a GitHub organization) maintains it in aiskillstore/marketplace, which has 430 GitHub stars. The repository holds 1,085 skills in this directory. The repository was last updated on October 7, 2026.
Source: aiskillstore/marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.