{"data":{"skill":{"slug":"jeffallan-flutter-expert","name":"flutter-expert","icon":"📦","repo":"https://github.com/jeffallan/claude-skills/tree/main/skills/flutter-expert/","status":"approved","author":"jeffallan","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"f77e1de2-a546-4181-905d-14e1c9f711b1","skill_id":"4b209bd5-2d8f-44cb-a17b-6e0241e0b313","version":2,"content_hash":"a32cdada8015f1b39e1de7423fe59869","risk_level":"safe","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":null,"manual_install_policy":null,"summary":"Static analysis reported external command, network, key, storage, reconnaissance, and weak-crypto patterns, but review found documentation-only Flutter and Dart examples. No code executes automatically, no secrets are accessed, and no prompt injection text was found.","remediation":[],"risk_factor_evidence":[],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[{"title":"False Positive: Markdown Backticks Flagged as Command Execution","verdict":"FALSE_POSITIVE","locations":[{"file":"SKILL.md","line_end":52,"line_start":47},{"file":"references/bloc-state.md","line_end":222,"line_start":36},{"file":"references/gorouter-navigation.md","line_end":118,"line_start":5},{"file":"references/performance.md","line_end":90,"line_start":5},{"file":"references/project-structure.md","line_end":94,"line_start":5},{"file":"references/riverpod-state.md","line_end":129,"line_start":5},{"file":"references/widget-patterns.md","line_end":119,"line_start":5}],"confidence":0.97,"description":"The external command alerts point to Markdown code fences, inline reference paths, Dart snippets, and Flutter CLI documentation. These examples are inert skill content and do not run commands automatically.","confidence_reasoning":"The reviewed locations are Markdown fences or inline code references. The only shell commands are Flutter profiling examples in documentation, with no autonomous execution path."},{"title":"False Positive: Flutter Key Syntax Flagged as Credential Material","verdict":"FALSE_POSITIVE","locations":[{"file":"references/widget-patterns.md","line_end":12,"line_start":12},{"file":"references/widget-patterns.md","line_end":41,"line_start":41},{"file":"references/widget-patterns.md","line_end":119,"line_start":119},{"file":"references/project-structure.md","line_end":104,"line_start":104},{"file":"references/riverpod-state.md","line_end":70,"line_start":70},{"file":"references/riverpod-state.md","line_end":94,"line_start":94},{"file":"references/gorouter-navigation.md","line_end":40,"line_start":40},{"file":"references/bloc-state.md","line_end":120,"line_start":120}],"confidence":0.99,"description":"The certificate and key alerts match Flutter widget constructor syntax such as super.key, Key, and route query key terms. No private keys, certificates, or credential files are present.","confidence_reasoning":"Every cited occurrence is ordinary Flutter API syntax or documentation table text. There is no secret value, encoded material, or file path to credential artifacts."},{"title":"False Positive: Weak Crypto Alerts Match Ordinary Words","verdict":"FALSE_POSITIVE","locations":[{"file":"SKILL.md","line_end":3,"line_start":3},{"file":"SKILL.md","line_end":22,"line_start":22},{"file":"SKILL.md","line_end":60,"line_start":60},{"file":"references/bloc-state.md","line_end":23,"line_start":23},{"file":"references/gorouter-navigation.md","line_end":72,"line_start":71},{"file":"references/widget-patterns.md","line_end":51,"line_start":38}],"confidence":0.95,"description":"The weak cryptography alerts match ordinary documentation text, including description, auth guidance, and desktop layout terms. No MD5, SHA1, DES, or cryptographic API use was found.","confidence_reasoning":"Manual review of the static locations found natural language and UI layout identifiers. There is no implementation of cryptographic functions or insecure algorithm selection."},{"title":"False Positive: System Reconnaissance Alerts Match Dart Examples","verdict":"FALSE_POSITIVE","locations":[{"file":"references/bloc-state.md","line_end":85,"line_start":84},{"file":"references/bloc-state.md","line_end":168,"line_start":167},{"file":"references/gorouter-navigation.md","line_end":25,"line_start":25},{"file":"references/project-structure.md","line_end":99,"line_start":96},{"file":"references/riverpod-state.md","line_end":43,"line_start":31}],"confidence":0.94,"description":"The reconnaissance alerts occur inside Flutter routing and state-management examples, such as route parameters, Todo methods, and widget callbacks. They do not inspect host system information.","confidence_reasoning":"The reviewed lines are application sample code, not shell commands or host probes. No uname, whoami, environment enumeration, or filesystem reconnaissance behavior appears."},{"title":"False Positive: Hardcoded URL Is Author Metadata","verdict":"FALSE_POSITIVE","locations":[{"file":"SKILL.md","line_end":6,"line_start":6}],"confidence":0.98,"description":"The network alert is a GitHub author URL in skill metadata. It is not a runtime endpoint and no data is sent to it by the skill.","confidence_reasoning":"The URL appears only in frontmatter metadata as the author attribution. There is no fetch, HTTP client, webhook, or exfiltration path associated with it."},{"title":"False Positive: Storage References Are Architecture Guidance","verdict":"FALSE_POSITIVE","locations":[{"file":"references/project-structure.md","line_end":71,"line_start":69},{"file":"references/project-structure.md","line_end":87,"line_start":87}],"confidence":0.96,"description":"The browser storage alert matches Flutter dependency and architecture guidance for shared preferences, Hive, and data layer responsibilities. The skill itself does not access browser storage.","confidence_reasoning":"The lines describe Flutter project structure and dependency choices. No executable code reads cookies, localStorage, sessionStorage, or browser credentials."}],"dangerous_patterns":[],"files_scanned":7,"total_lines":937,"audit_model":"codex","audited_at":"2026-06-30T03:59:48.345+00:00","created_at":"2026-06-30T04:44:53.160776+00:00","static_findings":[],"finding_verdicts":[],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"canonical install advisories are incomplete"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":0,"needsReviewCount":0,"falsePositiveCount":6,"agentAutoInstallPolicy":null,"manualInstallPolicy":null,"artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}