flutter-testing

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute standard Flutter and Dart development commands for testing and code generation. Specifically, it routes the agent to use flutter test, flutter drive, and dart run build_runner build. Additionally, it includes a local shell script, scripts/verify-examples.sh, used to validate the skill's own consistency, links, and adherence to modern Flutter API standards.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze existing project code (such as pubspec.yaml and files in test/) to generate appropriate testing suites. This represents a standard surface for indirect prompt injection where malicious instructions embedded in a user's codebase could influence the agent's behavior, although no specific exploitable patterns are introduced by the skill itself.
  • Ingestion points: Reads pubspec.yaml, existing test/ and integration_test/ directories, and project configuration files.
  • Boundary markers: None explicitly defined in the provided files.
  • Capability inventory: Execution of shell commands via flutter, dart, and bash for testing and linting.
  • Sanitization: None detected; the skill relies on the agent's internal reasoning and project inspection to determine appropriate actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 09:57 PM
Security Audit — agent-trust-hub — flutter-testing