service-boundary-and-native

Pass

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill's instructions in SKILL.md are purely architectural and procedural. There are no attempts to override agent behavior, bypass safety filters, or extract system prompts. Phrases like 'Non-negotiable rules' are used within the context of software design patterns.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: No sensitive file paths, hardcoded credentials, or unauthorized network operations were identified. The architectural patterns described (isolating SDKs behind interfaces) are actually security-positive by reducing the surface area of sensitive code.
  • [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The provided scripts (scripts/check-flavor-graph.sh and scripts/check-service-boundaries.sh) are local analysis tools. They utilize standard commands such as grep, find, and flutter pub deps. No remote scripts are downloaded or executed.
  • [DYNAMIC_EXECUTION]: All code examples and scripts are static. There is no use of eval(), exec(), or runtime code generation. The skill emphasizes static analysis and build-time configuration (flavors) over runtime detection.
  • [SAFE]: The skill serves as a best-practices guide for Flutter developers to maintain clean architecture and testability. All included scripts and code examples are benign and operate within the scope of the project's local environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 18, 2026, 05:44 PM
Security Audit — agent-trust-hub — service-boundary-and-native