developing-genkit-dart
Audited by Socket on Mar 11, 2026
1 alert found:
SecurityThe Genkit Dart skill documentation presents a coherent purpose-to-capability narrative for a Dart SDK and CLI tool, with a strong emphasis on plugins, flows, and schemantic-based data models. However, there is a notable security concern: installation is described via an unverified curl|bash flow from an external domain, without visible checksums, signatures, or pinning. This introduces supply-chain risk and warrants caution. Otherwise, the stated capabilities (code generation, tool/flow definitions, embeddings, and plugin integration) align with a legitimate developer tooling use-case, and data flows appear to be contained to standard CLI/plugin interactions with external AI services. Overall, classify as SUSPICIOUS due to the download-execute pattern and unverifiable dependencies, with a path toward Benign if provenance is improved (pinned versions, verified checksums, official registries, and transparent plugin integrity guarantees).