Mobile Security
SkillFiles & storageSecure Flutter token/PII storage, build-time secrets, network trust, and release hardening using OWASP Mobile practices. Use for secure storage, secret injection, certificate pinning, jailbreak/root risk, or release builds—not generic form validation, API error handling, auth-provider setup, or tests of existing security services.
Available today. Use it from your connected AI after setup.
No other account needed.
Connect ahel once, and every AI you use reads what you have installed.
Then ask your AI: use the Mobile Security skill
What this skill tells your AI
The instructions your AI receives, as published by hoangnguyen0403/agent-skills-standard in skills/flutter/flutter-security/SKILL.md and read by ahel’s review.
Priority: P0 (CRITICAL)
Implementation Workflow
- Store secrets securely — Use
flutter_secure_storagefor tokens/PII. Never useshared_preferencesfor sensitive data. - Externalize secrets — Never store API keys in Dart code. Use
--dart-defineor.envfiles. - Obfuscate releases — Build
--obfuscate --split-debug-info=./symbols. Deterrent only — move sensitive logic to backend. - Pin certificates —
dio_certificate_pinningfor high-security apps to prevent MITM. - Root detection —
flutter_jailbreak_detectionfor root/jailbreak checks in financial/sensitive apps. - Mask PII — Redact PII (email, phone) from all logs and analytics.
Secure Storage & Release Build Examples
See implementation examples for secure storage usage and obfuscated release build commands.
Reference & Examples
SSL Pinning & Secure Storage: references/REFERENCE.md.
Anti-Patterns
- No Secrets in SharedPreferences: Use
flutter_secure_storagefor tokens and PII - No Hardcoded API Keys: Use
--dart-defineor secure vaults for all secrets - No Unobfuscated Releases: Always build with
--obfuscate --split-debug-info - No PII in Logs: Mask or omit sensitive data from all logs and analytics events
Related Topics
common/security-standards | layer-based-clean-architecture | performance
Canonical response anchors
When this skill applies, preserve the following domain terminology or equivalent concrete examples in the answer when relevant:
- certificate pinning,SSL pinning
Remediation anchors
- Remediation anchors: root/jailbreak detection, --obfuscate, --split-debug-info
Signals
- GitHub stars
- 565
- Forks
- 163
- Last commit
- Sep 2026
Advanced
- Catalog kind
- skill
- Gateway key
flutter-security- Source
- github.com/hoangnguyen0403/agent-skills-standard