Flutter Security Audit

Audits Flutter mobile apps against OWASP Mobile Top 10 (2024) vulnerabilities. Trigger this skill before any production release, when the user mentions "security audit", "OWASP", "penetration test", "App Store rejection security", "hardcoded API key", "secrets in code", or any concern about leaked credentials, insecure storage, or weak crypto. Combines automated scanning (grep for hardcoded secrets, dependency CVE check, network security analysis) with manual checklist (storage, crypto, IPC, runtime protections). NOT a replacement for professional pentesting on apps handling financial/health data, but catches 90% of common issues. Use when this capability is needed.

tomevault-io d583833 2 files · 8.7 KB Updated

File contents

tomevault-io/skills-registry/tree/main/axisting--axistia-flutter-skills--flutter-security-audit commit d583833053

Frequently asked questions

npx skillmds@latest add tomevault-io/flutter-security-audit