state-management-auditor
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes shell commands including
grep,find,xargs,wc, andsortto analyze the Flutter project'spubspec.yamland Dart source files. These commands are used solely for static analysis of the codebase to identify state management patterns and inefficiencies. - [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data in the form of local source code and project configuration files which may contain adversarial instructions.
- Ingestion points: The agent reads all Dart files within the
lib/directory and the projectpubspec.yamlfile (SKILL.md, Step 1, Step 2). - Boundary markers: The skill does not implement delimiters or explicit instructions for the agent to ignore natural language instructions embedded within the code it analyzes.
- Capability inventory: The skill's capabilities are limited to file system read-access and reporting; there are no instructions for network access, remote code execution, or file writing.
- Sanitization: No sanitization, filtering, or escaping is applied to the content of the analyzed files before it is processed by the agent.
Audit Metadata