flutter-workflow
Pass
Audited by Gen Agent Trust Hub on Mar 11, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill defines a
PostToolUsehook in its metadata that automatically executes a shell command when a.dartfile is edited. The commandbash -c 'cd "$(git rev-parse --show-toplevel 2>/dev/null || pwd)" && dart analyze --no-fatal-infos 2>&1 | tail -5'is used to run the standard Dart static analyzer on the project. This is a common development practice and uses local system tools for linting purposes. - [PROMPT_INJECTION]: The skill instructions emphasize a rigorous workflow but do not contain patterns intended to override AI safety guidelines, bypass constraints, or extract system prompts.
- [DATA_EXFILTRATION]: There are no identified attempts to access sensitive local files or transmit data to external servers. The network-related MCP tool calls mentioned are part of the standard documentation-fetching workflow.
- [REMOTE_CODE_EXECUTION]: The skill does not contain logic for downloading and executing arbitrary scripts from the internet or performing unsafe dynamic code evaluation.
- [SAFE]: The skill focuses on improving Flutter code quality through a documentation-first approach and automated linting, which aligns with standard software development lifecycle practices.
Audit Metadata