flutter-state-and-data-fetching

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFE
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill explicitly forbids storing authentication tokens in plaintext or insecure locations like SharedPreferences. It mandates the use of flutter_secure_storage (Keychain/Keystore) and requires that tokens never be logged or included in crash/analytics payloads.
  • [DATA_EXFILTRATION]: The instructions include a requirement for a logging interceptor that redacts Authorization headers and PII (Personally Identifiable Information) before routing data to observability seams, preventing accidental data leaks.
  • [EXTERNAL_DOWNLOADS]: The skill recommends standard, industry-recognized Flutter packages (e.g., dio, flutter_secure_storage, riverpod, connectivity_plus, workmanager) which are well-maintained and appropriate for the declared development tasks.
  • [SAFE]: The skill implements a 'single-flight' token refresh mechanism which is a security best practice to prevent race conditions that could lead to session instability or unauthorized access attempts under heavy network concurrency.
  • [SAFE]: The skill follows an architectural alignment process by ingesting local configuration files (mobile-architecture.md, architecture/security). This workflow is well-defined:
  • Ingestion points: Reads local markdown files for architectural decisions.
  • Boundary markers: Extracts specific tables and sections (e.g., State Management Strategy table) to scope the generation.
  • Capability inventory: The skill generates standard Dart code for models, providers, and interceptors.
  • Sanitization: The agent acts as a code generator, translating documented requirements into code structures rather than executing external data as instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 08:35 AM
Security Audit — agent-trust-hub — flutter-state-and-data-fetching