flutter-app-scaffold-and-runtime

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements strict security measures by mandating the use of .gitignore for secrets and credentials (e.g., .env, *.jks, *.p12). It explicitly instructs the agent to avoid hardcoding API keys and to reference signing configuration via environment variables or CI secret stores.
  • [COMMAND_EXECUTION]: The skill uses local shell commands (flutter analyze, flutter build) to verify the generated scaffold's integrity. These operations are standard for development workflows and are used here for validation purposes rather than arbitrary execution.
  • [EXTERNAL_DOWNLOADS]: The skill references well-known and trusted dependencies including Flutter SDK components and established libraries like Firebase, Sentry, and GetIt. These references are pinned to specific versions to ensure build reproducibility and supply chain security.
  • [SAFE]: The skill processes local architecture documentation (mobile-architecture.md) to guide the scaffolding process. This is a functional requirement for the skill and does not introduce malicious behavior, as the skill maintains strict control over the generated file structure and output locations.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 08:35 AM
Security Audit — agent-trust-hub — flutter-app-scaffold-and-runtime