Back to skill

Security audit

Flutter Dev

Security checks for vulnerabilities and agentic risk

Overview

This Flutter guide is not malicious, but several copy-paste examples could expose sensitive app data or request broad permissions without enough safety guidance.

Review this skill before installing if your agents will generate production Flutter networking or mobile-permission code from it. Treat the networking snippets as patterns needing hardening: redact logs, disable body logging in production, allowlist cacheable endpoints, encrypt or avoid sensitive caches, clear user-specific caches on logout, and request mobile permissions only for features that truly need them.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
references/networking.md:96
Finding

Sensitive API Data Logged Without Redaction

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/networking.md:410
Finding

Authenticated GET Responses Persisted in Unencrypted Hive Cache

Content
View full analysis
options.uri.toString(); } ``` ### Technical Analysis The interceptor caches every successful GET response without evaluating whether the endpoint is public, authenticated, user-specific, or explicitly non-cacheable. The standard Hive box is opened without an encryption cipher, so serialized response data is persisted without application-level encryption. The cache key is only the request URI. It is not scoped to the authenticated user or session. The example also provides no logout cleanup, account-change inval ...[truncated 1746 chars]
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (12)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 120)May include surrounding context.

md
| iOS/Android/Web specific implementations | [Platform Integration](references/platform-specific.md) |

Hidden Instructions

High
Category
Prompt Injection
Confidence
70% confidence
Finding

Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Content

Scanner excerpt · references/platform-specific.md (reported line 266)May include surrounding context.

Info.plist Permissions

xml
<!-- ios/Runner/Info.plist -->
<key>NSCameraUsageDescription</key>
<string>This app needs camera access to take photos</string>

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The auto-save example transmits form data to the server after a debounce interval without any explicit user confirmation or warning that data will be sent automatically. In a development guide, this can normalize implementation of background transmission for potentially sensitive draft content, increasing privacy and compliance risk if developers copy the pattern into real forms handling personal or confidential data.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

This markdown file includes code that explicitly sets locale: const Locale('en'), which forces a specific language without user opt-in. The policy allows locale constraints only when documented and justified or when users are offered a choice, neither of which applies to this example snippet.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
83% confidence
Finding

The example returns const Locale('en') as the fallback locale, which imposes a specific language choice in natural-language behavior. Although the file later shows a language selector, this snippet still demonstrates forced English as the default rather than respecting system locale or requiring explicit user choice.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/networking.md (reported line 18)May include surrounding context.

md
ApiClient._internal() {
    dio = Dio(BaseOptions(
      baseUrl: 'https://api.example.com/v1',
      connectTimeout: const Duration(seconds: 10),
      receiveTimeout: const Duration(seconds: 30),
      sendTimeout: const Duration(seconds: 30),

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/networking.md (reported line 79)May include surrounding context.

md
ApiClient._internal() {
    dio = Dio(BaseOptions(
      baseUrl: 'https://api.example.com/v1',
      connectTimeout: const Duration(seconds: 10),
      receiveTimeout: const Duration(seconds: 30),
      sendTimeout: const Duration(seconds: 30),

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The disk cache example persists arbitrary GET response bodies to Hive without any filtering, classification, encryption, or retention warning. In a Flutter app, API responses often contain user profile data, tokens, or other sensitive information, so this pattern can lead to unintended local data retention and exposure on shared, rooted, backed-up, or compromised devices.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The guide includes broad iOS and Android permission examples for camera, photo library, microphone, location, storage, and internet even though the demonstrated code only shows simple platform detection, haptics, and basic device info retrieval. In a developer skill, copy-pastable permission blocks can lead consumers to over-request dangerous permissions, increasing privacy exposure, review risk, and attack surface beyond what the feature set actually requires.

Content

No source excerpt is available for this finding.

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/platform-specific.md (reported line 263)May include surrounding context.

iOS-Specific Configuration

Info.plist Permissions

xml
<!-- ios/Runner/Info.plist -->

Session Persistence

Medium
Category
Rogue Agent
Confidence
75% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/platform-specific.md (reported line 266)May include surrounding context.

iOS-Specific Configuration

Info.plist Permissions

xml
<!-- ios/Runner/Info.plist -->

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation demonstrates collecting device-identifying information such as device model, device name, manufacturer, and OS version without any privacy warning, minimization guidance, or explanation of acceptable use. While not directly exfiltrating data, this normalizes collecting fingerprinting-relevant attributes and may encourage downstream apps to gather personal or device-identifying data without consent or disclosure.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
references/forms.md:459