Agent skill

Flutter MCP Boundary Audit

by Arenukvern in Arenukvern/mcp_flutter

Generic contract/schema boundary audit across authoring, discovery, validation, and execute—detecting split-brain between listings and invoke paths, gateway divergence, and permissive placeholders.

MITAuto-check passedMobile

Install Flutter MCP Boundary Audit

skills CLI
$ npx skills add Arenukvern/mcp_flutter --skill flutter-mcp-boundary-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Arenukvern/mcp_flutter flutter-mcp-boundary-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Arenukvern/mcp_flutter.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugin/skills/flutter-mcp-boundary-audit .claude/skills/flutter-mcp-boundary-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
flutter-mcp-boundary-audit
GitHub stars
387
Token cost
~3k tokens
SKILL.md length
1,141 words
Files
2
Skills in repo
23
Repo updated
First seen
Licence
MIT

At a glance

Generic contract/schema boundary audit across authoring, discovery, validation, and execute—detecting split-brain between listings and invoke paths, gateway divergence, and permissive placeholders.

  • Works in 4 steps: List tools/resources (or OpenAPI GET)… → Invoke with missing required →… → Invoke with extra properties when schema… → …
  • Changing tool registration
  • SKILL.md covers When to run, Boundary checklist, Gateway divergence and Dual-path parity, plus 7 more sections
  • Calls rg

What it does

Flutter MCP Boundary Audit is an agent skill from Arenukvern/mcp_flutter. Generic contract/schema boundary audit across authoring, discovery, validation, and execute—detecting split-brain between listings and invoke paths, gateway divergence, and permissive placeholders. Use when changing tool registration, RPC/plugin registries, dynamic tools, MCP or WebMCP surfaces, CLI exec aliases, OpenAPI or JSON Schema contracts, migrators/codegen, bridge argument encoding, or platform docs that describe API contracts.

Its SKILL.md is about 3k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file (for example `reference.md`).

It sits in Mobile, covering Cross-platform mobile apps, MCP servers and Project scaffolding. It works with Model Context Protocol, Flutter and OpenAPI. The repository describes itself as: MCP Toolkit for Flutter AI Agent Driven Development (MCP/CLI + custom client side tools) - via closed feedback loop (visual & semantic snapshot) and high client side… The licence is MIT.

When your agent uses it

  • Changing tool registration
  • RPC/plugin registries
  • WebMCP surfaces
  • CLI exec aliases

Example prompts

  • “/flutter-mcp-boundary-audit”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. List tools/resources (or OpenAPI GET) shows required and strict additionalProperties where intended.
  2. Invoke with missing required → structured failure (ok: false, 4xx, or validation error)—before handler side effects.
  3. Invoke with extra properties when schema is strict → same failure mode.
  4. If dual paths exist, repeat on both catalog and runtime registration names.

What it can do on your machine

Read from SKILL.md and the folder at commit 62f3ee1. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • rg

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Flutter MCP Boundary Audit loads about 3k tokens when it runs. Until then it costs about 117 tokens; SKILL.md has 1,141 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~117
When it runs · the whole SKILL.md, loaded when a task matches
~3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Arenukvern/mcp_flutter at commit 62f3ee1, republished under its MIT licence (© Arenukvern). 1,141 words, ~3,022 tokens.

Download SKILL.mdSave it as .claude/skills/flutter-mcp-boundary-audit/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
flutter-mcp-boundary-audit
description
Generic contract/schema boundary audit across authoring, discovery, validation, and execute—detecting split-brain between listings and invoke paths, gateway divergence, and permissive placeholders. Use when changing tool registration, RPC/plugin registries, dynamic tools, MCP or WebMCP surfaces, CLI exec aliases, OpenAPI or JSON Schema contracts, migrators/codegen, bridge argument encoding, or platform docs that describe API contracts.
<!-- @FMT_MODE_PRELUDE -->

Contract boundary audit

Skill ID: flutter-mcp-boundary-audit — name is historical; content is repository-neutral. Same workflow applies to MCP stacks, RPC gateways, plugin registries, and OpenAPI-style contracts.

For mcp_flutter, use this skill to audit Flutter adapter parity: fmt_* catalog schemas, CLI exec, VM-service extension gateways, dynamic discovery, migrators, and consumer platform docs. Change app discovery or the Flutter bridge here; change canonical IntentCall registry/session semantics, schema policy, platform projection, or publish behavior upstream.

Find split-brain bugs: what clients see in listings, catalogs, or docs ≠ what runtime enforces on invoke—or validation exists on one gateway only.

Typical symptoms:

  • Advertised required fields differ from what invoke accepts (empty payload succeeds, wrong keys ignored)
  • Host/catalog path validates; in-process or extension path does not (or the reverse)
  • Migrator or codegen rewrites entries with empty or permissive schema placeholders
  • Same logical capability registered twice with different schemas (listing vs invoke, or path A vs path B)
  • Stale docs claim “always permissive” or “no validation” while code is fail-closed

When to run

Trigger (generic)Audit focus
Tool/handler authoring, schema attachment at registrationAuthoring → discovery payload
Dynamic or plugin registration on the app/runtime sideRuntime validate-before-handler
Server registry, forward/dispatch, catalog *_client_tool helpersRegistry listing + invoke
Host gateway (VM extension, IPC, HTTP proxy) before delegating to runtimeHost validate-before-delegate; fail-closed missing schema
In-process invoke (invokeDirect, browser hook, embedded bridge)Same schema as listing; validate before execute
Entry migrator / codegen from annotated sourcesSchema preservation, not permissive fallbacks
Shared schema module vs duplicate definitionsDual-path parity
Bridge handlers, non-scalar argumentsEncoding (JSON, protobuf, etc.) vs handler expectations
Platform / ADR / registration docsStale claims vs code

Also run after changes to JSON Schema, OpenAPI request bodies, protobuf RPC messages, or plugin manifest input shapes when multiple gateways consume the same logical tool.

Boundary checklist

Trace authoring → discovery → validation → execute for every touched tool or RPC:

StepQuestionWhere to look (your repo)
AuthoringDoes the canonical input schema reach the registration/descriptor type (not dropped at a toolkit/bridge wrapper)?Authoring layer / entry model / code generator output
AuthoringDo bridge tools encode non-scalar args consistently for legacy handlers?Bridge helpers, adapter layers
DiscoveryDoes dynamic registration send the full inputSchema (not {} or implicit-any)?App registration API, manifest emitter
DiscoveryDoes the host list/catalog tool expose the same schemas as the runtime registry?List-tools handler vs app registration
Server registryDoes registry intent/metadata use real schema, not a permissive placeholder?Registry builder, MCP tool → intent mapping
Validate (registry)Does forward/dispatch call validate before execute?Registry forward path
Validate (host gateway)Does the host gateway validate before delegating? Fail-closed if schema missing?Gateway implementation
Validate (runtime)Does the runtime callback validate before handler?Service extension / in-process hook
Validate (wire)If wire args are strings/maps, is coercion applied before strict validation on paths that see wire shape?Coercion module vs host-only typed JSON
Validate (in-process)Does direct invoke validate before execute?In-process entry invoke
Validate (CLI)Do CLI exec / catalog commands use the same schema as MCP listing?CLI dispatch vs server tools
ExecuteAny .execute( / handler dispatch without prior validate in production code?Grep (below)
MigratorDoes migration preserve primitive/required/additionalProperties from source schema?Migrator, codegen
DocsDo platform/registration docs match actual fail-closed behavior?Platform doc, ADRs

Gateway divergence

Same logical tool may flow through different gateways—each must agree on schema and validation order:

text
Authoring (entry / descriptor)
    ├─► Runtime registration ──► extension/callback ──► handler
    ├─► In-process register (WebMCP / embedded) ──► invokeDirect
    └─► Host list/catalog ──► catalog invoke ──► host gateway ──► runtime
Gateway roleMust validate beforeFail if schema missing?
Runtime callback (extension, plugin hook)handleryes (production tools)
Registry forwardexecute / handleryes
Host gateway (proxy to runtime)delegate callyes
In-process invokeexecuteyes
Catalog / fmt_* / CLI wrapperforward to runtimeyes (same as listing)
CLI execcommand dispatchyes

Red flag: validation only in tests, only on the catalog path, or only on listing—not on the path your change actually uses.

Wire coercion (when applicable)

Some stacks deliver string-key maps on the wire (VM service extensions, JSON-RPC with loose typing). Separate concerns:

MechanismRole
Coerce-for-schemaProperty-type coercion from wire strings before strict schema validation
Handler-side wire parsersOptional when handlers still read raw wire maps
Outbound wire encodingHandler args → wire-safe representation

Re-audit host gateway vs runtime callback if you add coercion on one side only—hosts that expect typed JSON must not assume runtime already coerced (and vice versa).

Show full SKILL.md (443 more words)Show less

Dual-path parity

One logical capability often exists twice:

PathTypical roleListing / invoke
Runtime / app dynamicRegistered in the running app or plugin hostExtension name, dynamic registry
Host catalogServer-side MCP tools, CLI aliases, OpenAPI routesPrefixed or bare names on wire

For each shared tool, compare:

  • required keys
  • additionalProperties: false (or equivalent strictness)
  • Host-only fields (e.g. connection) present on one path only
  • Property types / enums
  • Default values and coercion behavior

Document intentional deltas in your platform contract doc (not only in tests).

Red-flag grep

Run from your repository root. Adjust globs to your languages and package layout.

bash
# Empty or permissive advertised schemas (JSON Schema style)
rg "inputSchema:\s*const\s*\{\s*'type':\s*'object'" --glob "*.dart" -g '!test/fixtures/**' -g '!**/after_*.dart'
rg '"type"\s*:\s*"object"\s*,\s*\}' --glob "*.{dart,ts,js,json,yaml}"
rg "_emptyObjectSchema|additionalProperties:\s*true" --glob "*.{dart,ts,js}"

# OpenAPI / generic permissive bodies
rg "additionalProperties:\s*true" --glob "*.{yaml,yml,json}"
rg "schema:\s*\{\s*\}" --glob "*.{yaml,yml}"

# Execute without validate (review each hit; exclude tests/fixtures)
rg "\.execute\(" --glob "*.{dart,ts,js}" | rg -v "validate|test/|_test\.|\.test\."

# Direct invoke bypass
rg "invokeDirect|invoke_direct|directInvoke" --glob "*.{dart,ts,js}"
# Manual review: validate appears before execute on each path

# Permissive registry placeholders
rg "emptyObjectSchema|empty_object_schema|placeholder.*schema|inputSchemaFrom" --glob "*.{dart,ts,js}"

# Migrator stripping schemas
rg "inputSchema|input_schema" --glob "*migrate*"

# Duplicate registration (e.g. JS + native)
rg "registerTool|register_tool" --glob "*.{dart,ts,js}"

# Stale “always permissive” docs
rg -i "permissive|additionalProperties:\s*true|no validation|accepts anything" --glob "*.md"

# Bridge / JSON args
rg "jsonEncode|JSON\.encode|serialize.*argument" --glob "*{bridge,entry,adapter}*"

Add project-specific patterns after completing Adapting to your repo.

E2E proof

Run your integration tests that cover listing + invalid invoke (not a specific app path).

Checklist:

  1. List tools/resources (or OpenAPI GET) shows required and strict additionalProperties where intended.
  2. Invoke with missing required → structured failure (ok: false, 4xx, or validation error)—before handler side effects.
  3. Invoke with extra properties when schema is strict → same failure mode.
  4. If dual paths exist, repeat on both catalog and runtime registration names.

Optional: schema parity unit tests comparing shared module vs duplicate definitions (no device required).

Report template

markdown
## Finding: [title]
- **Severity**: P0 | P1 | P2
- **Boundary**: authoring | discovery | validation | execute
- **Gateway**: runtime-callback | registry | in-process | host-gateway | cli | migrator | docs
- **Files**: ...
- **Symptom**: clients/docs see X; runtime does Y
- **Fix**: ...
- **Proof**: test name or grep command

Tracker (optional)

If your repo uses a superpowers/tracker or hardening program, record new findings there or as issues—do not reopen completed items unless regression.

Adapting to your repo

Before auditing, fill this map (keep in audit notes or PR description):

RoleYour locationNotes
Authoringe.g. entry model, OpenAPI spec, @Tool annotationsWhere canonical schema is defined
Discoverye.g. registerDynamics, plugin manifest, MCP tools/listWhat clients read
Registry / cataloge.g. dynamic registry, server tool tableListing vs invoke entry points
Host gatewaye.g. VM extension proxy, API gateway, sidecarValidates before delegate?
Runtime callbacke.g. service extension, plugin host RPCValidates before handler?
In-process invokee.g. WebMCP, embedded JS bridgeSame as tools/list?
CLIe.g. exec, bare vs prefixed aliasesSame schema as MCP?
Shared schema modulee.g. interaction_input_schemas, OpenAPI componentsSingle source of truth?
Migrator / codegene.g. migrate agent-entriesPreserves required/properties?
Platform doce.g. INTENTCALL_PLATFORM.md, README contract sectionMatches fail-closed code?

Checklist

  • Map tool registration path (authoring → discovery).
  • Map listing gateway vs invoke gateway(s); list every hop.
  • Map schema representation (JSON Schema maps, OpenAPI, protobuf, Dart ObjectSchema, etc.).
  • Add 2–3 repo-specific red-flag greps (permissive placeholder, your invoke helper name).
  • Identify dual-path tools; note shared module or document intentional split.
  • Run integration test or manual proof for one strict tool on every gateway you touched.

Deep reference

Worked example (mcp_flutter), file map, and regression patterns: reference.md

When working in this monorepo only:

  • flutter-mcp-toolkit-custom-tools — authoring entries
  • flutter-mcp-toolkit-intentcall-migration — migrate agent-entries
  • flutter-mcp-toolkit-maintain-web — WebMCP / in-process invoke
  • flutter-mcp-cli-runtime-validation — runtime validate-runtime

© Arenukvern, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in plugin/skills/flutter-mcp-boundary-audit of Arenukvern/mcp_flutter.

  • SKILL.md
  • reference.md

Open the folder on GitHubat commit 62f3ee1

Compare with similar skills

Flutter MCP Boundary Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Flutter MCP Boundary Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Flutter MCP Boundary Audit this skillArenukvern/mcp_flutter387—~3kAutomated safety check: PassMIT
SpikardGoldziher/spikard124—~799Automated safety check: PassMIT
MCP Server Builderalirezarezvani/claude-skills28k—~985Automated safety check: PassMIT
Retrieving Developer Knowledgegoogle/skills21k—~2kAutomated safety check: PassApache-2.0
Create ProjectVeryGoodOpenSource/vgv-ai-flutter-plugin170—~1.2kAutomated safety check: PassMIT
OpenAPI to MCP Servermcp-use/mcp-use11k—~5.2kAutomated safety check: PassApache-2.0

Similar skills

  • Spikard

    Goldziher/spikard

    Scaffold Spikard projects and generate code from OpenAPI, AsyncAPI, OpenRPC, GraphQL, and Protobuf schemas using the Spikard CLI or its MCP server.

    124 GitHub stars~799 tokensUpdated today
    Backend & APIsAuto-check passed
  • MCP Server Builder

    alirezarezvani/claude-skills

    Design and ship production-ready MCP (Model Context Protocol) servers from OpenAPI contracts instead of hand-written tool wrappers.

    28k GitHub stars~985 tokensUpdated 1 mo ago
    Agent WorkflowsAuto-check passed
  • Official

    Searches, retrieves, and synthesizes official Google developer documentation across Google Cloud, AI/Gemini, Android, Chrome, Web, Flutter, Go, Firebase, and other Google developer platforms.

    21k GitHub stars~2k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Create Project

    VeryGoodOpenSource/vgv-ai-flutter-plugin

    Scaffold a new Dart or Flutter project from a Very Good CLI template, covering the flutterapp, dartpackage, flutterpackage, flutterplugin, dartcli, flamegame, and docssite templates, inferring the…

    170 GitHub stars~1.2k tokensUpdated 5 days ago
    MobileAuto-check passed
  • OpenAPI to MCP Server

    mcp-use/mcp-use

    Turns an OpenAPI or Swagger spec into an MCP server with the mcp-use TypeScript SDK, mapping each operation to a tool, wiring auth, testing and deploying.

    11k GitHub stars~5.2k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • API Endpoint Contract

    trycompai/comp

    The contract every new or modified API endpoint must follow so it is correct for the public OpenAPI spec, the MCP server (npm @trycompai/mcp-server), the ValidationPipe, and the docs.

    2k GitHub stars~2.7k tokensUpdated yesterday
    Backend & APIsAuto-check passed

More from Arenukvern/mcp_flutter

All 23 skills in this repo
  • Harness Engineering Lifecycle

    Arenukvern/mcp_flutter

    Design, implement, and integrate generalized validation harnesses across a producer-consumer boundary after a local harness contract exists.

    387 GitHub stars~1.6k tokensUpdated 8 days ago
    Auto-check passed
  • Mixture Of Experts

    Arenukvern/mcp_flutter

    Run a Mixture of Experts (MoE) audit on any topic, plan, codebase, evidence archive, or process.

    387 GitHub stars~2.3k tokensUpdated 8 days ago
    Auto-check passed
  • Multi Agent Handoff

    Arenukvern/mcp_flutter

    Plan and document handoffs, parent lane contracts, and parallel batch contracts between specialized AI agents (foreman, workers, reviewers).

    387 GitHub stars~2.7k tokensUpdated 8 days ago
    Auto-check passed
  • Plugin Marketplace Setup

    Arenukvern/mcp_flutter

    Designs public or private Agent Skill and plugin marketplaces for Cursor, Claude Code, Codex, Zed, Open Plugin, and npx skills—manifest layout, install matrix, and Skill Steward vs product boundaries.

    387 GitHub stars~2.9k tokensUpdated 8 days ago
    Auto-check passed
  • Release Changelog Harness

    Arenukvern/mcp_flutter

    Chooses ecosystem-native release and changelog tooling (Changesets, Melos, release-plz) plus binary distribution (GitHub Release tarballs, install.sh) when the product is an executable.

    387 GitHub stars~2.6k tokensUpdated 8 days ago
    Auto-check passed
  • Repository Governance Lifecycle

    Arenukvern/mcp_flutter

    Master orchestration for repository governance, North Star impact, sub-Star boundaries, and repair-first or evidence-first drift checks.

    387 GitHub stars~1.5k tokensUpdated 8 days ago
    Auto-check passed

Questions about Flutter MCP Boundary Audit

What does Flutter MCP Boundary Audit do?

Generic contract/schema boundary audit across authoring, discovery, validation, and execute—detecting split-brain between listings and invoke paths, gateway divergence, and permissive placeholders. Flutter MCP Boundary Audit is an agent skill from Arenukvern/mcp_flutter. Generic contract/schema boundary audit across authoring, discovery, validation, and execute—detecting split-brain between listings and invoke paths, gateway divergence, and permissive placeholders.

When should I use Flutter MCP Boundary Audit?

Flutter MCP Boundary Audit fits situations like: changing tool registration; RPC/plugin registries; webMCP surfaces; CLI exec aliases.

How do I install Flutter MCP Boundary Audit in Claude Code?

Run `npx skills add Arenukvern/mcp_flutter --skill flutter-mcp-boundary-audit -a claude-code`. Or copy the skill folder (plugin/skills/flutter-mcp-boundary-audit in Arenukvern/mcp_flutter) into .claude/skills/flutter-mcp-boundary-audit in your project. Claude Code loads it when a task matches its description.

How do I install Flutter MCP Boundary Audit in Codex?

Run `npx skills add Arenukvern/mcp_flutter --skill flutter-mcp-boundary-audit -a codex`. Or copy the skill folder (plugin/skills/flutter-mcp-boundary-audit in Arenukvern/mcp_flutter) into .agents/skills/flutter-mcp-boundary-audit in your project. Codex loads it when a task matches its description.

Can I use Flutter MCP Boundary Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Arenukvern/mcp_flutter --skill flutter-mcp-boundary-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/flutter-mcp-boundary-audit, .gemini/skills/flutter-mcp-boundary-audit, .github/skills/flutter-mcp-boundary-audit and .opencode/skills/flutter-mcp-boundary-audit in your project.

What does Flutter MCP Boundary Audit need to run?

Going by SKILL.md and its folder, Flutter MCP Boundary Audit needs the command-line tools its instructions call (rg).

Does Flutter MCP Boundary Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Flutter MCP Boundary Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Flutter MCP Boundary Audit use?

Flutter MCP Boundary Audit is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Flutter MCP Boundary Audit use?

About 3k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Flutter MCP Boundary Audit?

Skills that share tags, products or a category with Flutter MCP Boundary Audit: Spikard (Goldziher/spikard, 124 stars), MCP Server Builder (alirezarezvani/claude-skills, 28k stars), Retrieving Developer Knowledge (google/skills, 21k stars) and Create Project (VeryGoodOpenSource/vgv-ai-flutter-plugin, 170 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Flutter MCP Boundary Audit?

Arenukvern (a GitHub user) maintains it in Arenukvern/mcp_flutter, which has 387 GitHub stars. The repository holds 23 skills in this directory. The repository was last updated on October 3, 2026.

Source: Arenukvern/mcp_flutter on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.