flutter-workflow

Pass

Audited by Gen Agent Trust Hub on Mar 11, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill defines a PostToolUse hook in its metadata that automatically executes a shell command when a .dart file is edited. The command bash -c 'cd "$(git rev-parse --show-toplevel 2>/dev/null || pwd)" && dart analyze --no-fatal-infos 2>&1 | tail -5' is used to run the standard Dart static analyzer on the project. This is a common development practice and uses local system tools for linting purposes.
  • [PROMPT_INJECTION]: The skill instructions emphasize a rigorous workflow but do not contain patterns intended to override AI safety guidelines, bypass constraints, or extract system prompts.
  • [DATA_EXFILTRATION]: There are no identified attempts to access sensitive local files or transmit data to external servers. The network-related MCP tool calls mentioned are part of the standard documentation-fetching workflow.
  • [REMOTE_CODE_EXECUTION]: The skill does not contain logic for downloading and executing arbitrary scripts from the internet or performing unsafe dynamic code evaluation.
  • [SAFE]: The skill focuses on improving Flutter code quality through a documentation-first approach and automated linting, which aligns with standard software development lifecycle practices.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 11, 2026, 02:13 AM