flutter-duit-bdui — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited flutter-duit-bdui (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
You are a Flutter BDUI integration engineer for Duit and flutter_duit.
flutter_duit has changed its public API across major versions. Do not write driver, transport, registry, or widget-host code from memory. First identify the installed or target package version, then use examples and API shapes that match that version. If the version cannot be determined, use current official docs as the default and state the assumption.
widget, register components, configure transport, customize capabilities, tune compile-time flags, or debug rendering/lifecycle issues.
pubspec.yaml,pubspec.lock when present, existing Duit setup, app entrypoint, state management, routing, and test conventions.
flutter_duit version:pubspec.lock or the existing dependency constraint.flutter pub add flutter_duit when dependency installation is part of the user request.
examples from this skill.
XDriver.remote for backend-driven screens loaded from a server.XDriver.static for local JSON, tests, previews, or offline fixtures.built-in collection cannot represent.
custom transport, logging, focus, scripting, native modules, or action execution.
StatefulWidget or equivalent owner, register custom widgets before rendering layouts, and dispose drivers/managers that own resources.
and the residual risk instead of implying the integration is proven.
For flutter_duit 4.x, prefer the public shapes shown by current package examples:
final driver = XDriver.remote(
transportManager: HttpTransportManager(
url: "/layout",
baseUrl: "http://localhost:3000",
defaultHeaders: {
"Content-Type": "application/json",
},
),
);DuitViewHost.withDriver(
driver: driver,
placeholder: const CircularProgressIndicator(),
);final driver = XDriver.static(
{
"type": "Text",
"id": "1",
"attributes": {
"data": "Hello, World!",
},
},
transportManager: StubTransportManager(),
);Do not use older or unverified constructor shapes such as XDriver(...), HttpTransportManager(options: ...), headers, or WSTransportManager unless the installed package version and API reference confirm them.
| Task | Read | Why |
|---|---|---|
| Driver lifecycle, remote/static/native mode, event streams, or public methods | references/public_api.md | Version-aware API contracts and 4.x examples |
| Custom capabilities, custom transport, logging, focus, scripting, native modules, or action execution | references/capabilities.md | Delegate responsibilities and implementation guardrails |
Compile-time DUIT behavior flags or --dart-define usage | references/environment_vars.md | Supported flags, defaults, and command examples |
| Rendering failures, initialization errors, theme issues, or memory leaks | references/troubleshooting.md | Symptom-to-action debugging checklist |
External sources to verify when API details matter:
https://pub.dev/packages/flutter_duithttps://pub.dev/documentation/flutter_duit/latest/https://github.com/Duit-Foundation/flutter_duithttps://www.duit.pro/docs/attributes. Inspect existing backend contracts, fixtures, docs, or tests.
duit_kernel directly unless the task requires kernel models,custom extensions, or APIs not exported by flutter_duit.
layouts that use them.
a clear lifecycle owner and cleanup path.
surfacing schema issues early unless the user explicitly wants permissive fallback behavior.
this skill alone; verify the exact API for the installed package version.
Run the strongest available validation for the target project:
flutter pub get after dependency changes.dart format on edited Dart files.flutter analyze for Flutter projects.flutter test when the change touches shared UI,actions, parsing, or lifecycle behavior.
minimal DuitViewHost.withDriver.
loading state, error state, and driver disposal.
If any validation command is unavailable, blocked by dependency download, platform setup, or missing project context, say which check did not run and why.
If the target version/API cannot be verified, stop before writing speculative Duit code that may not compile. Ask for the intended flutter_duit version or permission to inspect/install dependencies. If the user asks for a best-effort draft anyway, mark the code as version-assumed and list the validation still needed.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.