flutter-performance-and-reliability
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface by consuming external project data to drive code generation. 1. Ingestion points: Extracts budget definitions and telemetry requirements from 'mobile-architecture.md' and 'architecture/performance'. 2. Boundary markers: No explicit markers or instructions are provided to the agent to treat the content of these files as untrusted. 3. Capability inventory: The skill generates Dart source code (budgets.dart) and modifies Ruby-based CI scripts (Fastfile), which can execute arbitrary logic in build environments. 4. Sanitization: No sanitization or validation logic is specified for the data extracted from the architecture files before interpolation into generated scripts.
Audit Metadata