Back to skill

Security audit

Flutter Master

Security checks across malware telemetry and agentic risk

Overview

This is a coherent Flutter development and audit skill with a broad trigger, but its file access and commands are disclosed and aligned with project review work.

Install if you want an opinionated Flutter review assistant. For quick Flutter questions, be aware it may load more audit guidance than needed, and only let it run the bundled audit script on projects you intentionally want scanned.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

High
Confidence
95% confidence
Finding
The activation criteria are excessively broad and explicitly instruct proactive triggering for nearly any Flutter-related mention, even for small or incidental requests. In an agent system, this can cause over-invocation of the skill, unnecessary context loading, and increased chance that the agent follows embedded operational guidance or executes bundled scripts when the user did not ask for an audit or deep review.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.