reversing-flutter-apps

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill directs the agen t to use local shell comm and s such as unzip, rg, strings, python3, and apk signer for binary analysis and manipulatio n.
  • [COMMAND_EXECUTION]: Instructs the use of ad b shell su -c to modify network routing via iptables on a connected Android device.
  • [EXTERNAL_DOWNLOADS]: Recom mend s using external resource s such as the blutter tool from GitHub (github.com/worawit/blutter).
  • [PROMPT_INJECTION]: Indirect prom pt injectio n surface detected.
  • Ingestio n points: The skill processe s external APK/IPA binarie s using variou s comm and-line utilitie s (SKIL L.md).
  • Boundary markers: No ne specified for handling binary output or extracted strings.
  • Capability inventor y: Local shell executio n, file system access, and remote device control.
  • Sanitizatio n: Absent; the skill doe s no t provide guidance on sanitizing data extracted from untrusted binarie s before it is used in subsequen t comm and s.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 01:17 AM
Security Audit — agent-trust-hub — reversing-flutter-apps