flutter-expert
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes project source code and configuration files which could contain malicious instructions designed to influence agent behavior.
- Ingestion points: Reads user-provided Dart files and project metadata (pubspec.yaml) during the development workflow.
- Boundary markers: Instructions do not specify the use of delimiters to isolate external file content from the agent's primary instructions.
- Capability inventory: Employs CLI tools including flutter analyze, flutter test, and flutter pub to interact with the project environment.
- Sanitization: No validation or sanitization of ingested file content is performed prior to processing or executing commands.
- [EXTERNAL_DOWNLOADS]: Downloads project dependencies and development utilities from the official package registry.
- Evidence: Utilizes flutter pub get and flutter pub global activate devtools for project setup and profiling.
- Source: Resources are retrieved from pub.dev, the well-known official package repository for the Flutter ecosystem.
Audit Metadata