flutter-in-app-purchases
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill requires the agent to ingest and analyze external project files, including
pubspec.yaml, SDK constraints, and native store configurations. These files represent a surface for indirect prompt injection where malicious instructions could be embedded in configuration comments or metadata.\n- Ingestion points: Project configuration files such aspubspec.yamland native store/platform configurations are read during the 'Preflight' phase defined inSKILL.md.\n- Boundary markers: The instructions do not specify the use of delimiters or 'ignore' commands when processing these external files.\n- Capability inventory: The skill is designed to 'Implement, repair, or review' code, which involves modifying the application's source code and configuration based on the ingested data.\n- Sanitization: There are no instructions for sanitizing or validating the content of the external files before the agent acts upon them.
Audit Metadata