service-boundary-and-native
Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill's instructions in
SKILL.mdare purely architectural and procedural. There are no attempts to override agent behavior, bypass safety filters, or extract system prompts. Phrases like 'Non-negotiable rules' are used within the context of software design patterns. - [DATA_EXPOSURE_AND_EXFILTRATION]: No sensitive file paths, hardcoded credentials, or unauthorized network operations were identified. The architectural patterns described (isolating SDKs behind interfaces) are actually security-positive by reducing the surface area of sensitive code.
- [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The provided scripts (
scripts/check-flavor-graph.shandscripts/check-service-boundaries.sh) are local analysis tools. They utilize standard commands such asgrep,find, andflutter pub deps. No remote scripts are downloaded or executed. - [DYNAMIC_EXECUTION]: All code examples and scripts are static. There is no use of
eval(),exec(), or runtime code generation. The skill emphasizes static analysis and build-time configuration (flavors) over runtime detection. - [SAFE]: The skill serves as a best-practices guide for Flutter developers to maintain clean architecture and testability. All included scripts and code examples are benign and operate within the scope of the project's local environment.
Audit Metadata