flutter-setup-localization

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill documents the standard and official workflow for Flutter localization (i18n). It uses the built-in Flutter localization generator and the widely-used intl package.
  • [COMMAND_EXECUTION]: The skill utilizes standard Flutter CLI commands (flutter pub add, flutter pub get) to manage project dependencies and trigger the built-in code generation process. These are routine development actions.
  • [EXTERNAL_DOWNLOADS]: The skill adds the intl package from the official package registry (pub.dev) and the flutter_localizations package from the official Flutter SDK. Both represent well-known, trusted, and standard resources for the Flutter ecosystem.
  • [DYNAMIC_EXECUTION]: The setup enables Flutter's generate: true flag, which automatically compiles App Resource Bundle (.arb) files into Dart code at build time. This is a standard and intended behavior for this framework.
  • [INDIRECT_PROMPT_INJECTION]: The skill describes a process that ingests external data (ARB files) into a code generation pipeline. It follows best practices by including use-escaping: true in the l10n.yaml configuration, which helps mitigate potential injection risks during the generation of localization classes.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 02:38 AM
Security Audit — agent-trust-hub — flutter-setup-localization