stream-flutter

Pass

Audited by Gen Agent Trust Hub on Aug 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is authored by GetStream and exclusively uses official GetStream resources, including public Flutter packages (stream_chat_flutter, stream_video_flutter, stream_feeds) and domains (getstream.io). All external dependencies are standard libraries fetched from official registries like pub.dev.
  • [COMMAND_EXECUTION]: The skill requests permission to execute specific Bash commands (ls, grep, find, cat, flutter pub) and Stream CLI commands (getstream token, getstream env, getstream api, etc.). These tools are strictly scoped to project discovery, dependency resolution, and credential provisioning as part of the SDK integration workflow.
  • [DATA_EXFILTRATION]: No patterns of unauthorized data collection or exfiltration were detected. The skill provides clear rules against hardcoding API secrets and instructs users to manage sensitive tokens using standard secure methods like dart_defines.json or backend-issued JWTs.
  • [PROMPT_INJECTION]: The instructional language is structural and focused on maintaining state machine logic (e.g., intent classification). There are no attempts to override agent safety protocols or bypass model restrictions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 14, 2026, 12:31 PM
Security Audit — agent-trust-hub — stream-flutter