Agent skill

Python Web App Security Audit

by aiskillstore in aiskillstore/marketplace

Run defensive pre-release security tests for Python web applications.

MITAuto-check: notesBackend & APIs

Install Python Web App Security Audit

skills CLI
$ npx skills add aiskillstore/marketplace --skill python-web-app-security-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install aiskillstore/marketplace python-web-app-security-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/aiskillstore/marketplace.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/glenskii/python-web-app-security-audit .claude/skills/python-web-app-security-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
python-web-app-security-audit
GitHub stars
430
Token cost
~1.2k tokens
SKILL.md length
503 words
Files
28 (incl. scripts, references, assets)
Skills in repo
1,085
Repo updated
First seen
Licence
MIT

At a glance

Run defensive pre-release security tests for Python web applications.

  • Works in 4 steps: Install the dependencies in the target… → Copy the bundled suite into the target… → In the copied security/ directory, copy… → …
  • ASGI services: the common interface between Python web apps and servers
  • SKILL.md covers Scope, Prepare the suite, Operating rules and Report the result, plus 2 more sections
  • Runs Python scripts from its folder; calls pip, python and pytest

What it does

Python Web App Security Audit is an agent skill from aiskillstore/marketplace. Run defensive pre-release security tests for Python web applications. Use for FastAPI, Django, Flask, and ASGI services: the common interface between Python web apps and servers. Tests authentication, authorization, hostile input, headers, CORS, cookies, rate limits, errors, and configuration to return evidence-backed findings and clear test boundaries.

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 32 other files, including scripts, reference files and assets (for example `README.md`, `agents/openai.yaml` and `assets/security-audit-report-template.md`).

It sits in Backend & APIs, covering Backend development, Security review and Rate limiting. It works with Python, Django, FastAPI and Flask. The repository describes itself as: Security-audited skills for Claude, Codex & Claude Code. One-click install, quality verified. The licence is MIT.

When your agent uses it

  • ASGI services: the common interface between Python web apps and servers
  • Tasks that involve Backend development
  • Tasks that involve Security review

Example prompts

  • “/python-web-app-security-audit”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Install the dependencies in the target project's isolated environment.
  2. Copy the bundled suite into the target project without overwriting an existing security directory.
  3. In the copied security/ directory, copy .env.test.template to .env.test. Supply an app import path, routes, rate limit, permitted origin…
  4. From the target project root, run the suite.

What it can do on your machine

Read from SKILL.md and the folder at commit 4ac52da. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python, from the files we listed), which the agent can run.

    Shell commands in SKILL.md call:

    • pip
    • python
    • pytest

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use pip, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Python Web App Security Audit loads about 1.2k tokens when it runs, and up to ~3k if it reads all its reference files. Until then it costs about 96 tokens; SKILL.md has 503 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~96
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:33
    ty/`, `pytest.ini` when absent, and the `.env.test.template` file. It never creates a credentials file.
  • NoteMentions a .env fileSKILL.md:35
    the copied `security/` directory, copy `.env.test.template` to `.env.test`. Supply an app import path, routes, rate lim

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from aiskillstore/marketplace at commit 4ac52da, republished under its MIT licence (© aiskillstore). 503 words, ~1,230 tokens.

Download SKILL.mdSave it as .claude/skills/python-web-app-security-audit/SKILL.md (or your agent's skills folder). This skill also uses 27 other files; get the full folder from GitHub.
name
python-web-app-security-audit
description
Run defensive pre-release security tests for Python web applications. Use for FastAPI, Django, Flask, and ASGI services: the common interface between Python web apps and servers. Tests authentication, authorization, hostile input, headers, CORS, cookies, rate limits, errors, and configuration to return evidence-backed findings and clear test boundaries.
license
MIT
metadata.version
1.1.0

Python Web App Security Audit

Run a configurable pytest suite against a local Python web application before release. It uses ASGI, the interface between a Python web app and its server, so the checks can exercise FastAPI, Django, Flask through an adapter, and comparable services without opening a public server.

Scope

The bundled checks cover authentication, authorization, input validation, response headers, CORS, cookies, rate limits, error handling, HTTP method handling, and unsafe configuration. Read setup and boundaries, framework adapters, route configuration, fixture safety, and assertion catalog before adapting the suite to an application.

Do not represent a passing run as a penetration test or proof of production security. The suite does not verify deployment TLS, a WAF, dependency vulnerabilities, external infrastructure, or controls it cannot reach through the configured test application.

Prepare the suite

  1. Install the dependencies in the target project's isolated environment.

    bash
    pip install "pytest>=8" "pytest-asyncio>=0.24" "httpx>=0.27" python-dotenv
  2. Copy the bundled suite into the target project without overwriting an existing security directory.

    bash
    python scripts/prepare_security_suite.py C:\path\to\your-project

    The helper copies security/, pytest.ini when absent, and the .env.test.template file. It never creates a credentials file.

  3. In the copied security/ directory, copy .env.test.template to .env.test. Supply an app import path, routes, rate limit, permitted origin, and dedicated test credentials. Keep .env.test out of version control.

  4. From the target project root, run the suite.

    bash
    pytest security/ -v

Operating rules

  1. Test actual application behavior, not framework defaults.
  2. Use dedicated test accounts and non-production data.
  3. Configure route variables before treating a failing default route as a defect.
  4. Inspect every failure before assigning a release gate.
  5. Keep application-layer findings separate from infrastructure findings.
  6. Report both verified results and test boundaries.
  7. Do not add checks that create accounts, alter records, or issue destructive database commands. This bundled suite is non-destructive.
Show full SKILL.md (212 more words)Show less

Report the result

Use the report template, release decision guide, and continuous integration guide. For every finding, state the affected route or control, evidence, severity, recommended fix, and what was not tested. End with one of these release decisions:

  • BLOCKED: A confirmed issue must be fixed before release.
  • REVIEW REQUIRED: A material risk remains and needs an owner decision.
  • PASS: The configured checks found no blocking or review-level issue. This does not prove complete security.

Suite contents

FilePurpose
security/conftest.pyApplication import, test client, authentication fixtures, and route helpers
security/test_headers.pyHeader presence and directive quality
security/test_validation.pyHostile input, malformed payloads, and type coercion
security/test_auth.pyAuthentication enforcement and enumeration resistance
security/test_authorization.pyObject ownership, role boundaries, and mass assignment
security/test_rate_limit.pyThreshold and 429 response checks
security/test_errors.pyError sanitization and internal detail leakage
security/test_cors.pyOrigin restrictions and preflight handling
security/test_cookies.pyCookie flag enforcement
security/test_config.pyDebug exposure, method handling, and configuration checks

Boundaries

This skill does not replace manual security assessment, dependency scanning, production HTTPS verification, WAF validation, or dynamic scanning. Add an application-specific CSRF test when state-changing requests use cookie authentication.

The bundled suite does not create accounts, delete records, or execute schema-changing database commands. Assess any registration or other write flow only in an application-owned test suite with a disposable database and explicit cleanup.

© aiskillstore, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 27 other files (scripts, references, assets) in skills/glenskii/python-web-app-security-audit of aiskillstore/marketplace.

  • SKILL.md
  • LICENSE
  • README.md
  • agents/openai.yaml
  • assets/security-audit-report-template.md
  • docs/continuous-integration-guide.md
  • docs/release-decision-guide.md
  • pytest.ini
  • references/assertion-catalog.md
  • references/fixture-safety.md
  • references/framework-adapters.md
  • references/route-configuration.md
  • references/setup-and-boundaries.md
  • requirements.txt
  • scripts/prepare_security_suite.py
  • security
  • … and 12 more

Open the folder on GitHubat commit 4ac52da

Compare with similar skills

Python Web App Security Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Python Web App Security Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Python Web App Security Audit this skillaiskillstore/marketplace430—~1.2kAutomated safety check: NotesMIT
Fix Slow Endpointvpcarlos/profyle123—~2.1kAutomated safety check: PassMIT
Framework Migration AssistantArabelaTso/Skills-4-SE253—~1.9kAutomated safety check: PassApache-2.0
Sentry Python SDKgetsentry/sentry-for-ai268—~4.1kAutomated safety check: PassApache-2.0
Python Appservice Deploymicrosoft/GitHub-Copilot-for-Azure2551 repos~688Automated safety check: PassMIT
Python Devdoccker/cc-use-exp1.1k—~790Automated safety check: PassCustom licence

Similar skills

  • Fix Slow Endpoint

    vpcarlos/profyle

    Diagnose and fix a slow endpoint or request in a Python web app (FastAPI, Flask, Django, Tornado, any ASGI/WSGI framework) using real Profyle/VizTracer traces, then prove the fix by replaying the…

    123 GitHub stars~2.1k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Framework Migration Assistant

    ArabelaTso/Skills-4-SE

    Automatically migrate Python web applications between frameworks (Flask → FastAPI, Django → FastAPI).

    253 GitHub stars~1.9k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Sentry Python SDK

    getsentry/sentry-for-ai

    Official

    Full Sentry SDK setup for Python. An agent skill from getsentry/sentry-for-ai.

    268 GitHub stars~4.1k tokensUpdated today
    Backend & APIsAuto-check passed
  • Python Appservice Deploy

    microsoft/GitHub-Copilot-for-Azure

    Official

    Deploy Python (Flask/Django/FastAPI) code to Azure App Service Linux.

    255 GitHub starsUsed in 1 repo~688 tokens
    Backend & APIsAuto-check passed
  • Python Dev

    doccker/cc-use-exp

    Python 开发规范。当用户操作 .py、pyproject.toml、requirements.txt、setup.py 文件, 或涉及 FastAPI、Django、Flask、pytest、asyncio 开发时触发。

    1.1k GitHub stars~790 tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Fastapi Templates

    jh941213/my-cc-harness

    Production-grade FastAPI project creation and setup guide. An agent skill from jh941213/my-cc-harness.

    126 GitHub stars~945 tokensUpdated 2 mo ago
    Backend & APIsAuto-check passed

More from aiskillstore/marketplace

All 1,085 skills in this repo
  • Code Stats

    aiskillstore/marketplace

    Analyze codebase with tokei (fast line counts by language) and difft (semantic AST-aware diffs).

    430 GitHub starsUsed in 2 repos~697 tokens
    Auto-check: notes
  • Data Processing

    aiskillstore/marketplace

    Process JSON with jq and YAML/TOML with yq. An agent skill from aiskillstore/marketplace.

    430 GitHub starsUsed in 1 repo~720 tokens
    Auto-check: notes
  • Doc Scanner

    aiskillstore/marketplace

    Scans for project documentation files (AGENTS.md, CLAUDE.md, GEMINI.md, COPILOT.md, CURSOR.md, WARP.md, and 15+ other formats) and synthesizes guidance.

    430 GitHub starsUsed in 1 repo~644 tokens
    Auto-check: notes
  • File Search

    aiskillstore/marketplace

    Modern file and content search using fd, ripgrep (rg), and fzf.

    430 GitHub starsUsed in 1 repo~598 tokens
    Auto-check: notes
  • Find Replace

    aiskillstore/marketplace

    Modern find-and-replace using sd (simpler than sed) and batch replacement patterns.

    430 GitHub starsUsed in 1 repo~527 tokens
    Auto-check: notes
  • Investigating Codebases

    aiskillstore/marketplace

    Automatically activated when user asks how something works, wants to understand unfamiliar code, needs to explore a new codebase, or asks questions like "where is X implemented?", "how does Y…

    430 GitHub starsUsed in 1 repo~2.7k tokens
    Auto-check: notes

Questions about Python Web App Security Audit

What does Python Web App Security Audit do?

Run defensive pre-release security tests for Python web applications. Python Web App Security Audit is an agent skill from aiskillstore/marketplace. Run defensive pre-release security tests for Python web applications.

When should I use Python Web App Security Audit?

Python Web App Security Audit fits situations like: ASGI services: the common interface between Python web apps and servers; tasks that involve Backend development; tasks that involve Security review.

How do I install Python Web App Security Audit in Claude Code?

Run `npx skills add aiskillstore/marketplace --skill python-web-app-security-audit -a claude-code`. Or copy the skill folder (skills/glenskii/python-web-app-security-audit in aiskillstore/marketplace) into .claude/skills/python-web-app-security-audit in your project. Claude Code loads it when a task matches its description.

How do I install Python Web App Security Audit in Codex?

Run `npx skills add aiskillstore/marketplace --skill python-web-app-security-audit -a codex`. Or copy the skill folder (skills/glenskii/python-web-app-security-audit in aiskillstore/marketplace) into .agents/skills/python-web-app-security-audit in your project. Codex loads it when a task matches its description.

Can I use Python Web App Security Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add aiskillstore/marketplace --skill python-web-app-security-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/python-web-app-security-audit, .gemini/skills/python-web-app-security-audit, .github/skills/python-web-app-security-audit and .opencode/skills/python-web-app-security-audit in your project.

What does Python Web App Security Audit need to run?

Going by SKILL.md and its folder, Python Web App Security Audit needs Python for the scripts in its folder and the command-line tools its instructions call (pip, python and pytest). Our summary lists: Python 3.

Does Python Web App Security Audit access the network?

SKILL.md contains no URLs. Its commands use pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Python Web App Security Audit safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Python Web App Security Audit use?

Python Web App Security Audit is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Python Web App Security Audit use?

About 1.2k tokens (SKILL.md is roughly 4.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.7k tokens, read only when the agent opens those files.

What are the alternatives to Python Web App Security Audit?

Skills that share tags, products or a category with Python Web App Security Audit: Fix Slow Endpoint (vpcarlos/profyle, 123 stars), Framework Migration Assistant (ArabelaTso/Skills-4-SE, 253 stars), Sentry Python SDK (getsentry/sentry-for-ai, 268 stars) and Python Appservice Deploy (microsoft/GitHub-Copilot-for-Azure, 255 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Python Web App Security Audit?

aiskillstore (a GitHub organization) maintains it in aiskillstore/marketplace, which has 430 GitHub stars. The repository holds 1,085 skills in this directory. The repository was last updated on October 7, 2026.

Source: aiskillstore/marketplace on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.