flutter-expert
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to use standard Flutter CLI tools, including
flutter pub get,flutter test, andflutter analyze. These commands are used for their intended purpose within a mobile development workflow. - [EXTERNAL_DOWNLOADS]: The skill references an external documentation site hosted on GitHub Pages and implies the use of the official Dart package registry (
pub.dev). These references are standard for the Flutter ecosystem and do not point to untrusted or suspicious sources. - [INDIRECT_PROMPT_INJECTION]: The skill identifies a potential surface for indirect prompt injection as it processes user-provided source code and executes analysis tools on that code. This is a common characteristic of development-oriented skills and is documented here for awareness, though no specific exploitation patterns were identified.
- Ingestion points: Processes user-provided Flutter/Dart source files and
pubspec.yamlconfiguration files. - Boundary markers: No specific delimiters or safety instructions are defined to separate untrusted code from the agent's instructions.
- Capability inventory: Includes shell command execution capabilities via Flutter CLI tools (
flutter analyze,flutter test). - Sanitization: No explicit sanitization or validation of the ingested user code is mentioned prior to tool execution.
Audit Metadata