widget-composition
Pass
Audited by Gen Agent Trust Hub on Aug 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists of technical documentation and best practices for Flutter development, with no evidence of malicious intent, prompt injection, or data exfiltration.- [COMMAND_EXECUTION]: The skill includes a local shell script,
scripts/check-widget-composition.sh, which is used to identify common anti-patterns in Dart code viagrep. This script operates locally and does not perform network activities or privilege escalation.- [EXTERNAL_DOWNLOADS]: The documentation contains links to official development resources from the Flutter, Riverpod, and Dart websites. These are standard references and do not represent a security risk.- [INDIRECT_PROMPT_INJECTION]: The skill has a minimal attack surface for indirect prompt injection because it analyzes project source code. However, the analysis is limited to search operations viagrepand does not involve executing or evaluating the content of the analyzed files. Ingestion points: Project source code in thelib/directory. Boundary markers: Not present. Capability inventory: Local file search viagrep. Sanitization: Not applicable for read-only search operations.
Audit Metadata