flutter-state-and-data-fetching
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFE
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill explicitly forbids storing authentication tokens in plaintext or insecure locations like
SharedPreferences. It mandates the use offlutter_secure_storage(Keychain/Keystore) and requires that tokens never be logged or included in crash/analytics payloads. - [DATA_EXFILTRATION]: The instructions include a requirement for a logging interceptor that redacts
Authorizationheaders and PII (Personally Identifiable Information) before routing data to observability seams, preventing accidental data leaks. - [EXTERNAL_DOWNLOADS]: The skill recommends standard, industry-recognized Flutter packages (e.g.,
dio,flutter_secure_storage,riverpod,connectivity_plus,workmanager) which are well-maintained and appropriate for the declared development tasks. - [SAFE]: The skill implements a 'single-flight' token refresh mechanism which is a security best practice to prevent race conditions that could lead to session instability or unauthorized access attempts under heavy network concurrency.
- [SAFE]: The skill follows an architectural alignment process by ingesting local configuration files (
mobile-architecture.md,architecture/security). This workflow is well-defined: - Ingestion points: Reads local markdown files for architectural decisions.
- Boundary markers: Extracts specific tables and sections (e.g., State Management Strategy table) to scope the generation.
- Capability inventory: The skill generates standard Dart code for models, providers, and interceptors.
- Sanitization: The agent acts as a code generator, translating documented requirements into code structures rather than executing external data as instructions.
Audit Metadata