flutter-add-integration-test

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes standard Flutter development commands such as flutter pub add for dependency management, flutter drive for test execution, and flutter build apk for CI/CD preparation. These are legitimate uses of the command line for Flutter app development.\n- [INDIRECT_PROMPT_INJECTION]: The skill uses tools to read and interact with the UI of the application being tested, such as get_widget_tree and find.text. This creates a surface where text within the application could be interpreted by the agent during exploration.\n
  • Ingestion points: UI widget tree inspection via MCP and test assertions within SKILL.md.\n
  • Boundary markers: Not used; standard application interaction tools are employed.\n
  • Capability inventory: The agent has capabilities to execute shell commands (flutter drive) and interact with the application state via MCP tools.\n
  • Sanitization: Not explicitly present; behavior depends on the Flutter framework and MCP server implementation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 02:39 AM
Security Audit — agent-trust-hub — flutter-add-integration-test