widget-composition

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists of technical documentation and best practices for Flutter development, with no evidence of malicious intent, prompt injection, or data exfiltration.- [COMMAND_EXECUTION]: The skill includes a local shell script, scripts/check-widget-composition.sh, which is used to identify common anti-patterns in Dart code via grep. This script operates locally and does not perform network activities or privilege escalation.- [EXTERNAL_DOWNLOADS]: The documentation contains links to official development resources from the Flutter, Riverpod, and Dart websites. These are standard references and do not represent a security risk.- [INDIRECT_PROMPT_INJECTION]: The skill has a minimal attack surface for indirect prompt injection because it analyzes project source code. However, the analysis is limited to search operations via grep and does not involve executing or evaluating the content of the analyzed files. Ingestion points: Project source code in the lib/ directory. Boundary markers: Not present. Capability inventory: Local file search via grep. Sanitization: Not applicable for read-only search operations.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 01:01 PM
Security Audit — agent-trust-hub — widget-composition