reversing-flutter-apps
Pass
Audited by Gen Agent Trust Hub on Jul 30, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill directs the agen t to use local shell comm and s such as
unzip,rg,strings,python3, andapk signerfor binary analysis and manipulatio n. - [COMMAND_EXECUTION]: Instructs the use of
ad b shell su -cto modify network routing viaiptableson a connected Android device. - [EXTERNAL_DOWNLOADS]: Recom mend s using external resource s such as the
bluttertool from GitHub (github.com/worawit/blutter). - [PROMPT_INJECTION]: Indirect prom pt injectio n surface detected.
- Ingestio n points: The skill processe s external APK/IPA binarie s using variou s comm and-line utilitie s (SKIL L.md).
- Boundary markers: No ne specified for handling binary output or extracted strings.
- Capability inventor y: Local shell executio n, file system access, and remote device control.
- Sanitizatio n: Absent; the skill doe s no t provide guidance on sanitizing data extracted from untrusted binarie s before it is used in subsequen t comm and s.
Audit Metadata