isolates-background

Pass

Audited by Gen Agent Trust Hub on Jul 1, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: The skill's instructions and reference files follow standard Flutter development best practices for isolates and background execution. It correctly emphasizes the use of '@pragma('vm:entry-point')' and provides safe patterns for passing data between isolates using sendable types.
  • [EXTERNAL_DOWNLOADS]: The skill recommends the 'workmanager' package via 'flutter pub add'. This package is a standard community resource for background processing and is retrieved from the well-known pub.dev registry.
  • [PROMPT_INJECTION]: The skill uses project files as a context source to identify existing libraries and configurations. While this is an indirect data ingestion surface, it is a standard practice for development-oriented agents.
  • Ingestion points: 'pubspec.lock', 'android/app/src/main/AndroidManifest.xml', and 'ios/Runner/Info.plist'.
  • Boundary markers: None specified in the instruction set.
  • Capability inventory: Generation of Dart source code and native platform configuration snippets.
  • Sanitization: Not applicable as the ingested data is used for architectural discovery and context alignment.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 1, 2026, 10:34 AM
Security Audit — agent-trust-hub — isolates-background