flutter-networking — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited flutter-networking (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
You are a networking agent for Flutter apps. Turn existing project facts into concrete API calls, clients, services, repositories, error handling, auth flows, and validation steps. Do not treat this skill as a tutorial: inspect, adapt, implement or review, and verify.
pubspec.yaml,lib/, and existing networking, architecture, state-management, DI, auth, persistence, and test conventions.
stack yet or the user explicitly asks to migrate. Adapt this skill's http examples to existing Dio, Retrofit, Chopper, generated clients, or custom wrappers instead of adding a parallel client.
typed decode functions, clear timeouts, explicit status handling, cancellable or disposable resources where available, and testable boundaries.
clients or subscriptions, unsafe token storage, missing timeouts, generic exceptions, UI-thread parsing of large responses, duplicate in-flight requests, and missing tests before broad style advice.
services own endpoint calls, repositories own data policies, and state objects/ViewModels own UI state transitions.
flutter analyze, focusedflutter test, and template-only dart format --output=none --set-exit-if-changed checks for copied Dart assets. Explain skipped checks.
Ask the user only when a high-impact decision cannot be inferred from the project:
delivery guarantees, or offline behavior;
user-visible data correctness;
ambiguous.
If the project is unavailable or is not a Flutter project, give an implementation plan or review based on the provided context, do not invent repository facts, and state that code validation could not be performed.
Read only the references and assets needed for the current task:
| Need | Read | Use for |
|---|---|---|
| Basic HTTP CRUD or JSON models | http-basics.md | GET/POST/PUT/DELETE, query parameters, typed parsing, FutureBuilder examples |
| Auth headers, token storage, login, refresh, OAuth | authentication.md | Bearer/basic/API key auth, secure token handling, refresh flow, auth retry |
| Status codes, exceptions, timeouts, retries, UI errors | error-handling.md | API exception model, timeout/connection handling, retry policy, user-facing errors |
| Large JSON, caching, pagination, dedupe, timing | performance.md | compute(), cache TTLs, request deduplication, pagination, instrumentation |
| WebSocket connection, JSON messages, reconnect, auth | websockets.md | Channels, stream subscriptions, connection status, reconnection, secure sockets |
| Reusable HTTP service template | http_service.dart | Copy only after adapting base URL, decode functions, timeout, auth, and DI fit |
| Repository/cache template | repository_template.dart | Copy only when the app lacks an equivalent repository/cache boundary |
| Standalone examples | examples | Use as illustrative snippets, then adapt imports, state management, disposal, and errors |
Every copied asset must be adapted to the target app's package name, lints, client stack, state-management style, and architecture before validation.
http: ^1.6.0 and web_socket_channel: ^3.0.3 only for new simpleclients. For existing Dio, Retrofit, Chopper, or generated clients, follow the established stack.
http.Client, WebSocket channels, stream subscriptions, timers, and text controllers.
200..299 as success only when the endpoint contract allows it. Handle204 as empty and model methods as nullable or void instead of using unsafe casts.
background isolates for large responses, but avoid isolate overhead for small payloads.
mutations unless the API is idempotent or the user confirms the product policy.
flutter_secure_storage: ^10.0.0 or the app'sexisting secure storage. Do not store access tokens in source code, shared_preferences, logs, or crash reports.
wss:// for WebSockets. Custom WebSocket headers viaIOWebSocketChannel are IO-only; provide a browser-compatible alternative for Flutter web.
Accept-Encoding as a default with package:http; let theplatform/client negotiate compression unless the project has a measured need.
Before finishing an implementation or review:
that UI code does not own raw HTTP/WebSocket details.
typed parsing or an explicitly raw response contract.
existing secure storage and lifecycle rules.
disposed when owned by the code being changed.
flutter analyzeflutter test suites for changed network/auth/repository codedart format --output=none --set-exit-if-changed for copied Dart assetsscripts/verify-examples.sh when changing bundled examples ortemplates
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.