flutter-testing
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill presents an attack surface for indirect prompt injection because it analyzes external project files and has shell execution capabilities. \n
- Ingestion points: The agent reads project files like
pubspec.yamland files within thetest/,integration_test/, andtest_driver/directories as specified in the workflow section ofSKILL.md. \n - Boundary markers: The instructions lack specific markers or delimiters to help the agent distinguish untrusted project data from its own internal instructions. \n
- Capability inventory: The skill allows for the execution of multiple shell commands such as
flutter test,dart run build_runner build,flutter drive, and a local validation scriptbash scripts/verify-examples.sh. \n - Sanitization: There is no mention of sanitizing, escaping, or validating the content ingested from external project files before it is processed by the agent.\n- [COMMAND_EXECUTION]: Core functionality of the skill involves the execution of various shell commands. The
Mandatory Validationsection ofSKILL.mdinstructs the agent to run commands includingflutter test,dart run build_runner build, andbash flutter-testing/scripts/verify-examples.shto verify changes and test implementations.\n- [DYNAMIC_EXECUTION]: The skill includes a maintenance script,scripts/verify-examples.sh, that utilizes dynamic code execution. The script usesruby -eto execute Ruby logic for parsing YAML frontmatter and checking for broken links within the skill's markdown files.
Audit Metadata