Back to skill

Security audit

Flutter Updater

Security checks for vulnerabilities and agentic risk

Overview

This Flutter updater mostly matches its stated purpose, but it needs review because it automatically runs unaudited helper programs found through PATH before user confirmation and can make broad project changes.

Review this before installing. Use it only in a clean, backed-up Flutter/Dart workspace, verify the installed helper binaries and PATH resolution, and expect changes to pubspec files, lockfiles, source/test code, SDK state, build artifacts, and .flutter_updater reports/state.

Vulnerability Patterns
  • Tool Hijacking and SpoofingModifies or replaces tools so legitimate-looking calls execute attacker logic
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T07 · Tool Hijacking and Spoofing

Error
Location
SKILL.md:27
Finding

PATH-Based Helper Suite Hijacking

Content
View full analysis
/dev/null)" 2>/dev/null || echo "$HOME/.claude/skills/flutter-updater/bin")" _SKILL_BASE="$(dirname "$_SKILL_DIR" 2>/dev/null || echo "$HOME/.claude/skills/flutter-updater")" ``` ### Technical Analysis The mandatory preamble uses `which flutter-updater-config` to locate an executable through the process's `PATH`. It then treats the executable's parent hierarchy as the trusted Skill installation directory. Subsequent phases execute numerous programs relative to the resulting `$_SKILL_BASE`, including configuration, version-checking, project-state, target-detection, SDK-check, classification, changelog, and report-saving helpers. Consequently, control of the first `flutter-updater-config` entry in `PATH` effectively provides control over the helper suite used by the Skill. The fallback path does not protect against this issue because it is only selected when lookup fails. An attacker-controlled executable that resolves successfully prevents the fallback from being used. The commands are also run automatically during the mandatory preamble, before the user approves any SDK or breaking dependency update. The project artifact contains only Markdown files and does not include the referenced helper implementations. Their integrity and internal network behavior therefore cannot be independently verified through this artifact. ### Attack Path 1. An attacker obtains the ability to create files in a directory that appears before the legitimate Skill directory in the victim's `PATH`. This could be a compromised development tool directory, user-writable local binary directory, or manipulated shell environment. 2. The attacker creates an executable named `flutter-updater-config` in that directory. 3. The attacker places additiona ...[truncated 1082 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:345
Finding

Predictable Temporary Report File Allows Symlink-Based File Overwrite

Content
View full analysis
/tmp/flutter_updater_report_$$.md << 'REPORT' REPORT ``` ```bash _FLUTTER_VER=$(flutter --version --machine 2>/dev/null | python3 -c "import json,sys; print(json.load(sys.stdin).get('frameworkVersion','unknown'))" 2>/dev/null || echo "unknown") # Default save location: .flutter_updater/reports/ inside the project # User can override by setting FLUTTER_UPDATER_REPORT_DIR in their shell _REPORT_DIR="${FLUTTER_UPDATER_REPORT_DIR:-.flutter_updater/reports}" "$_SKILL_BASE/bin/flutter-updater-save-report" "$_FLUTTER_VER" "/tmp/flutter_updater_report_$$.md" "$_REPORT_DIR" ``` ```bash rm -f /tmp/flutter_updater_report_$$.md ``` ### Technical Analysis The report is written directly into the shared `/tmp` directory using a filename based only on the shell process ID (`$$`). Process IDs are observable or potentially predictable, and the redirection does not request exclusive file creation. Standard shell output redirection follows symbolic links. If another local user creates the anticipated pathname as a symbolic link before the redirection occurs, the shell can truncate and overwrite the link target. No private temporary directory, ownership check, restrictive `umask`, or secure creation primitive is used. The same predictable path is subsequently passed to the report-saving helper and removed. This creates additional opportunities for local interference between creation, consumption, and cleanup. ### Attack Path 1. A local attacker monitors process creation or otherwise determines or predicts the shell PID used by the Skill. 2. Before the report redirection executes, the attacker creates `/tmp/flutter_updater_report_.md` as a symbolic link to a file writable by the victim. 3. The Skill executes the `cat >` redirection. 4. The ...[truncated 905 chars]
Remediation
View remediation
Vulnerability Patterns
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (5)

Self-Modification

High
Category
Rogue Agent
Confidence
98% confidence
Finding

The preamble performs a self-update/version-check by executing helper binaries from a path derived from the local environment before any project validation or user confirmation. This creates a trust boundary problem: a compromised or replaced skill installation can run arbitrary code automatically whenever the skill is invoked, making the updater itself an execution vector.

Content

Scanner excerpt · SKILL.md (reported line 26)May include surrounding context.

Preamble (run first, always)

bash
# Self-update check (silent if up to date)
_SKILL_DIR="$(dirname "$(which flutter-updater-config 2>/dev/null)" 2>/dev/null || echo "$HOME/.claude/skills/flutter-updater/bin")"
_SKILL_BASE="$(dirname "$_SKILL_DIR" 2>/dev/null || echo "$HOME/.claude/skills/flutter-updater")"
_UPD=$("$_SKILL_BASE/bin/flutter-updater-version-check" 2>/dev/null || true)

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
85% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 369)May include surrounding context.

Clean up:

bash
rm -f /tmp/flutter_updater_report_$$.md

Report Template

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The README prominently advertises automatic SDK, dependency, and code changes, including auto-fixes and rollback behavior, but it does not give an upfront warning that running the skill will modify the workspace. Users may invoke it expecting analysis only, and unintentionally permit broad edits to source code and dependency state. In the context of an agent skill that can run multi-step update and build commands, this increases the risk of accidental disruptive changes or unsafe trust in automated modifications.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The description emphasizes automatic updating, auto-fixing, rollback, and QA, but does not clearly warn that the skill will modify dependency manifests, lockfiles, source files, and local project state. In context, this omission increases the chance that users approve or trigger the skill without understanding its write scope and code-changing behavior.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill advertises broad trigger phrases such as "update flutter", "update dependencies", and "keep flutter up to date", which can cause the agent to invoke it in situations where the user did not intend extensive automated modifications. Because this skill performs package upgrades, code edits, builds, and report writes, accidental invocation can lead to unexpected project changes and execution of numerous commands.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.