A community-driven registry for Claude, Cursor, Windsurf, Cline & more. Not affiliated with Anthropic.
Are you the author? Sign in to claim
Flutter APK/AAB security SKILL.md for OpenClaw, Codex, Claude Code, and other AI coding agents
FlutterGuard is an agent-native APK/AAB security review skill for Flutter Android releases.
It is a pure agent skill for Claude Code, Codex, Cursor, OpenClaw, Gemini CLI, and other coding agents. Install or reference the single skill, then ask your agent to inspect a Flutter Android release artifact before shipping.
FlutterGuard is not a CLI. It is not an APK scanner app. It is not a static analyzer. It is one operational agent skill plus safety boundaries for APK/AAB security review.
Use this repository directly with any agent platform that supports local skills, instruction packs, or project-level agent guidance. The skill entrypoint is the root SKILL.md.
Recommended install:
SKILL.mdThen ask:
Use FlutterGuard to review this Flutter APK before release.
Codex:
AGENTS.md.SKILL.md.Claude Code:
SKILL.md, into your Claude Code skills location.OpenClaw:
Other agents:
SKILL.md.AGENTS.md as repository-level behavior guidance if your platform supports it.libapp.so.SKILL.md
Use when an APK/AAB artifact exists or the user asks for Flutter Android artifact safety review.
FlutterGuard APK Security Report
Artifact: build/app/outputs/flutter-apk/app-release.apk
Flutter Evidence: confirmed
Status: RISKY
Score: 72/100
Critical:
- None found from available evidence.
High Risk:
- android:allowBackup is enabled for an app that appears to handle account data.
Evidence: AndroidManifest.xml application node.
Recommended action: Review backup policy and disable or constrain backup after human approval.
Warnings:
- Staging API hostname appears in libapp.so strings.
Evidence: lib/arm64-v8a/libapp.so strings, value redacted to host only.
Informational:
- Package: com.example.app
- Target SDK: 35
- ABIs: arm64-v8a, armeabi-v7a
- Detected services: Firebase, Sentry
Requires Human Approval:
- Backup behavior change
- Endpoint migration or rotation strategy
SKILL.md: the installable FlutterGuard skill.AGENTS.md: project-level guidance for Codex-style agents working with this repo.SECURITY.md: reporting and safety policy.FlutterGuard should not silently auto-fix sensitive production behavior.
Human approval is required for:
Safe agent work includes artifact inspection, evidence collection, Markdown reports, checklist notes, test suggestions, and non-invasive recommendations.
FlutterGuard is currently a single agentic skill. The repository intentionally contains no CLI engine, generated binaries, APK fixtures, build output, scan outputs, installers, or CI wrappers.
1000+ skills curated from Anthropic, Vercel, Stripe, and other engineering teams
Claude Code skill for YouTube creators — channel audits, video SEO, retention scripts, thumbnails, content strategy, Sho
Design enforcement with memory — keeps your UI consistent across a project
AI image generation skill for Claude Code -- Creative Director powered by Gemini