flutter-testing
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute standard Flutter and Dart development commands for testing and code generation. Specifically, it routes the agent to use
flutter test,flutter drive, anddart run build_runner build. Additionally, it includes a local shell script,scripts/verify-examples.sh, used to validate the skill's own consistency, links, and adherence to modern Flutter API standards. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze existing project code (such as
pubspec.yamland files intest/) to generate appropriate testing suites. This represents a standard surface for indirect prompt injection where malicious instructions embedded in a user's codebase could influence the agent's behavior, although no specific exploitable patterns are introduced by the skill itself. - Ingestion points: Reads
pubspec.yaml, existingtest/andintegration_test/directories, and project configuration files. - Boundary markers: None explicitly defined in the provided files.
- Capability inventory: Execution of shell commands via
flutter,dart, andbashfor testing and linting. - Sanitization: None detected; the skill relies on the agent's internal reasoning and project inspection to determine appropriate actions.
Audit Metadata