dart-cognitive-complexity

Pass

Audited by Gen Agent Trust Hub on Oct 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests Dart and Flutter source code files and directories (e.g., lib/, test/) for analysis.\n
  • Ingestion points: Reads files in the project workspace to evaluate cognitive complexity.\n
  • Boundary markers: The skill requires the creation of a persistent triage report (complexity_triage_report.md) and a user confirmation gate before any code mutations are performed, providing significant oversight.\n
  • Capability inventory: The skill uses dart run, dart test, and flutter test, which can execute code within the project context. It also performs file writes to create reports and temporary artifacts.\n
  • Sanitization: No specific sanitization of the analyzed code is described, which is standard for static analysis and testing tools but presents a surface for indirect instructions to be processed by the agent.\n- [EXTERNAL_DOWNLOADS]: The skill fetches Dart packages from the public Dart registry (pub.dev) at runtime.\n
  • Evidence: dart run cognitive_complexity@^0.3.0 and dart run api_summary@^1.1.0.\n
  • Context: These packages are authored by the skill's author (kevmoo) and are established tools for Dart development.\n- [REMOTE_CODE_EXECUTION]: Downloads and executes external code via the Dart SDK's package runner.\n
  • Evidence: The use of dart run with versioned package identifiers (cognitive_complexity@^0.3.0, api_summary@^1.1.0) triggers a download and execution of the specified tool.\n- [COMMAND_EXECUTION]: Executes various shell commands to perform analysis, testing, and file management.\n
  • Evidence: dart pub get, dart format, dart analyze, dart test, git diff, and shell piping/redirection (> /tmp/api_before.txt).
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 5, 2026, 08:59 AM