developing-genkit-dart

Warn

Audited by Socket on Mar 11, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

The Genkit Dart skill documentation presents a coherent purpose-to-capability narrative for a Dart SDK and CLI tool, with a strong emphasis on plugins, flows, and schemantic-based data models. However, there is a notable security concern: installation is described via an unverified curl|bash flow from an external domain, without visible checksums, signatures, or pinning. This introduces supply-chain risk and warrants caution. Otherwise, the stated capabilities (code generation, tool/flow definitions, embeddings, and plugin integration) align with a legitimate developer tooling use-case, and data flows appear to be contained to standard CLI/plugin interactions with external AI services. Overall, classify as SUSPICIOUS due to the download-execute pattern and unverifiable dependencies, with a path toward Benign if provenance is improved (pinned versions, verified checksums, official registries, and transparent plugin integrity guarantees).

Confidence: 62%Severity: 72%
Audit Metadata
Analyzed At
Mar 11, 2026, 07:45 PM
Package URL
pkg:socket/skills-sh/firebase%2Fagent-skills%2Fdeveloping-genkit-dart%2F@19d3a74e1de90200cc076d9b8bc31ae5c2127e7b