flutter-expert

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to use standard Flutter CLI tools, including flutter pub get, flutter test, and flutter analyze. These commands are used for their intended purpose within a mobile development workflow.
  • [EXTERNAL_DOWNLOADS]: The skill references an external documentation site hosted on GitHub Pages and implies the use of the official Dart package registry (pub.dev). These references are standard for the Flutter ecosystem and do not point to untrusted or suspicious sources.
  • [INDIRECT_PROMPT_INJECTION]: The skill identifies a potential surface for indirect prompt injection as it processes user-provided source code and executes analysis tools on that code. This is a common characteristic of development-oriented skills and is documented here for awareness, though no specific exploitation patterns were identified.
  • Ingestion points: Processes user-provided Flutter/Dart source files and pubspec.yaml configuration files.
  • Boundary markers: No specific delimiters or safety instructions are defined to separate untrusted code from the agent's instructions.
  • Capability inventory: Includes shell command execution capabilities via Flutter CLI tools (flutter analyze, flutter test).
  • Sanitization: No explicit sanitization or validation of the ingested user code is mentioned prior to tool execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 05:57 PM
Security Audit — agent-trust-hub — flutter-expert