how-to-send-push-notifications-on-flutter-web-fcm
Pass
Audited by Gen Agent Trust Hub on Feb 16, 2026
Risk Level: LOW
Full Analysis
- EXTERNAL_DOWNLOADS (LOW): The
firebase-messaging-sw.jsfile usesimportScriptsto load Firebase SDKs fromgstatic.com. This is a trusted Google-controlled domain, qualifying for a severity downgrade per security guidelines.- INDIRECT_PROMPT_INJECTION (LOW): The skill establishes an ingestion point for external data via FCM push notifications (setBackgroundMessageHandlerand Dart stream). However, the capability is limited to UI notifications and console logging, presenting no path for agent instruction override.- CREDENTIALS_UNSAFE (INFO): The configuration object contains placeholders likeAPI_KEYandPROJECT_ID. These are standard instructional markers for user input and do not represent a leak of sensitive credentials.
Audit Metadata