flutter-dio-multi-service

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides instructional code and architecture for Flutter networking. It demonstrates best practices such as: using flutter_secure_storage for sensitive token management, centralizing authentication logic in interceptors to handle session expiry (401 errors), implementing a shared PersistCookieJar for consistent session state across multiple microservices, and using typed wrappers and response envelope validation to ensure data integrity.\n- [INDIRECT_PROMPT_INJECTION]: The networking architecture ingests and processes data from multiple external microservices, which is a standard behavior for networking skills.\n
  • Ingestion points: ApiService and AuthInterceptor process response data from microservice endpoints (SKILL.md).\n
  • Boundary markers: ApiResponseHelper provides basic envelope validation but lacks explicit text sanitization.\n
  • Capability inventory: The skill utilizes network access (Dio), local secure storage (FlutterSecureStorage), and file system access (path_provider) (SKILL.md).\n
  • Sanitization: JSON structure validation is present; however, no specific filtering for adversarial instructions is implemented.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 02:38 AM
Security Audit — agent-trust-hub — flutter-dio-multi-service