flutter-state-management

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: No malicious patterns, obfuscation, or unauthorized exfiltration attempts were detected. The skill provides standard boilerplate and architectural guidance for production-grade Flutter applications. It demonstrates the use of a logging interceptor and secure token storage, which are standard developer practices.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines patterns for processing data from external sources such as deep links (via GoRouter) and API responses (via Dio). This constitutes an ingestion surface for untrusted data. The documentation suggests using structured data models (JSON parsing) for these inputs, which helps mitigate schema confusion and injection risks. 1. Ingestion points: GoRouter pathParameters and Dio API response data in SKILL.md. 2. Boundary markers: Absent. 3. Capability inventory: Network requests (Dio) and navigation (GoRouter) in SKILL.md. 4. Sanitization: Present (implemented via typed Data Models like ProductModel).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 02:38 AM
Security Audit — agent-trust-hub — flutter-state-management