flutter-navigation
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external project files (e.g., pubspec.yaml, Dart source files) which could theoretically contain instructions designed to influence the agent's behavior during refactoring or migration tasks.
- Ingestion points: Local Flutter project files including pubspec.yaml, lib/ directory, and platform-specific configuration files (AndroidManifest.xml, Runner.entitlements).
- Boundary markers: Absent for ingested project data, though instructions advise the agent to inspect and adapt rather than blindly copy.
- Capability inventory: The agent can write Dart code, modify platform configuration files, and execute local development tools such as flutter analyze, flutter test, adb, and xcrun.
- Sanitization: The skill recommends using Uri for building locations but lacks explicit sanitization instructions for other data ingested from project files.
Audit Metadata