flutter-ai-integration
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill follows security best practices by explicitly advising against embedding API keys or secrets in client-side code, such as Dart source, assets, or obfuscated builds.
- [SAFE]: It provides comprehensive guidance on mitigating Indirect Prompt Injection risks by instructing developers to treat model output and tool arguments as untrusted and to validate them against strict schemas.
- [SAFE]: The skill promotes the principle of least privilege for tool execution, requiring explicit user confirmation for consequential actions and discouraging the automatic execution of generated markup, URLs, or commands.
- [SAFE]: External references point exclusively to official Google/Flutter documentation, which are trusted sources for development guidelines.
Audit Metadata