Skip to content
Back to skills

Flutter Security

ASecurity

Enforce OWASP Mobile security standards for Flutter apps. Use when storing sensitive data, making network calls, handling tokens/PII, or preparing release builds.

  • 549 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added June 6, 2026
developmentapibackendsecurityperformance

Works with

  • api

Security analysis

A100/100

Pro scans all 5 files and shows the line behind each finding

Scanned June 6, 2026

npx -y skills add HoangNguyen0403/agent-skills-standard --skill flutter-security --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Flutter Security?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Flutter Security
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/hoangnguyen0403-flutter-security/badge)](https://www.skillsdirectory.com/skills/hoangnguyen0403-flutter-security)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: flutter-security
description: Enforce OWASP Mobile security standards for Flutter apps. Use when storing sensitive data, making network calls, handling tokens/PII, or preparing release builds.
metadata:
  triggers:
    files:
    - 'lib/infrastructure/**'
    - 'pubspec.yaml'
    keywords:
    - secure_storage
    - obfuscate
    - jailbreak
    - pinning
    - PII
    - OWASP
---

# Mobile Security

## **Priority: P0 (CRITICAL)**

## Implementation Workflow

1. **Store secrets securely** — Use `flutter_secure_storage` for tokens/PII. Never use `shared_preferences` for sensitive data.
2. **Externalize secrets** — Never store API keys in Dart code. Use `--dart-define` or `.env` files.
3. **Obfuscate releases** — Build `--obfuscate --split-debug-info=./symbols`. Deterrent only — move sensitive logic to backend.
4. **Pin certificates** — `dio_certificate_pinning` for high-security apps to prevent MITM.
5. **Root detection** — `flutter_jailbreak_detection` for root/jailbreak checks in financial/sensitive apps.
6. **Mask PII** — Redact PII (email, phone) from all logs and analytics.

### Secure Storage & Release Build Examples

See [implementation examples](references/implementation.md) for secure storage usage and obfuscated release build commands.

## Reference & Examples

SSL Pinning & Secure Storage: [references/REFERENCE.md](references/REFERENCE.md).

## Anti-Patterns

- **No Secrets in SharedPreferences**: Use `flutter_secure_storage` for tokens and PII
- **No Hardcoded API Keys**: Use `--dart-define` or secure vaults for all secrets
- **No Unobfuscated Releases**: Always build with `--obfuscate --split-debug-info`
- **No PII in Logs**: Mask or omit sensitive data from all logs and analytics events

## Related Topics

common/security-standards | layer-based-clean-architecture | performance

Files in this skill

  • SKILL.md1.8 KB
  • evals/evals.json1.6 KB
  • references/REFERENCE.md394 B
  • references/implementation.md439 B
  • references/network-security.md702 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…