Skip to content
Back to skills

Flask

ASecurity

Best practices for Flask web development including routing, blueprints, and testing.

  • 2,483 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added August 31, 2026
testingsqlflasktestingapidatabase

Works with

  • cli
  • api

Security analysis

A100/100

Scanned August 31, 2026

npx -y skills add microsoft/debugpy --skill flask --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Flask?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Flask
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/microsoft-flask/badge)](https://www.skillsdirectory.com/skills/microsoft-flask)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: flask
description: Best practices for Flask web development including routing, blueprints, and testing.
---

# Skill: Flask

Best practices for Flask web development including routing, blueprints, and testing.

## When to Use

Apply this skill when building Flask web applications or APIs — routing, blueprints, extensions, and testing.

## Project Structure

-   Use the application factory pattern (`create_app()`) to avoid global state and enable testing.
-   Organize features into Blueprints; register them in the factory.
-   Keep configuration in a `config.py` with classes like `DevelopmentConfig`, `ProductionConfig`.

## Routing and Views

-   Prefer explicit HTTP method decorators (`@app.get`, `@app.post`) over generic `@app.route` with `methods=[...]`.
-   Validate request data early; return 400 errors for malformed input before processing.
-   Use `flask.abort()` with appropriate HTTP codes rather than returning error responses manually.

## Extensions

-   Initialize extensions lazily with `ext.init_app(app)` inside the factory, not at module level.
-   Common extensions: Flask-SQLAlchemy, Flask-Migrate, Flask-Login, Flask-WTF, Flask-CORS.

## Testing

-   Use `app.test_client()` for HTTP-level tests and `app.test_request_context()` for unit tests.
-   Use pytest fixtures to create the app and client; scope appropriately (`session` for the app, `function` for the client).
-   Set `TESTING=True` and use a separate test database.

## Pitfalls

-   Never use the development server (`app.run()`) in production — use Gunicorn or uWSGI.
-   Avoid storing mutable state on the `app` object; use `g` for request-scoped data.
-   Never hardcode `SECRET_KEY` — load from environment variables.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…