Agent skill

Dart Rules

by softspark in softspark/ai-toolkit

Dart/Flutter coding rules: style, patterns, security, testing.

Apache-2.0Auto-check passedMobile

Install Dart Rules

skills CLI
$ npx skills add softspark/ai-toolkit --skill dart-rules -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install softspark/ai-toolkit dart-rules --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/softspark/ai-toolkit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/app/skills/dart-rules .claude/skills/dart-rules && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
dart-rules
GitHub stars
179
Token cost
~3.8k tokens
SKILL.md length
1,767 words
Files
1
Skills in repo
112
Repo updated
First seen
Licence
Apache-2.0

At a glance

Dart/Flutter coding rules: style, patterns, security, testing.

  • Tasks that involve Cross-platform mobile apps
  • SKILL.md covers Naming, Null Safety, Classes and Functions, plus 21 more sections
  • Calls dart and flutter

What it does

Dart Rules is an agent skill from softspark/ai-toolkit. Dart/Flutter coding rules: style, patterns, security, testing. Triggers: .dart, pubspec.yaml, Flutter, Riverpod, Bloc, widget, StatelessWidget, StatefulWidget.

Its SKILL.md is about 3.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Mobile, covering Cross-platform mobile apps. It works with Flutter and Dart. The repository describes itself as: Professional-grade AI coding toolkit: 94 skills, 44 agents, multi-platform (Claude, Cursor, Windsurf, Copilot, Gemini, Cline, Roo Code, Aider, Augment, Antigravity, Codex CLI… The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Cross-platform mobile apps

Example prompts

  • “/dart-rules”

Requirements

  • Pre-approved tools (allowed-tools): Read

What it can do on your machine

Read from SKILL.md and the folder at commit d64db2b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • dart
    • flutter

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • docs.flutter.dev

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Dart Rules loads about 3.8k tokens when it runs. Until then it costs about 43 tokens; SKILL.md has 1,767 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~43
When it runs · the whole SKILL.md, loaded when a task matches
~3.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from softspark/ai-toolkit at commit d64db2b, republished under its Apache-2.0 licence (© softspark). 1,767 words, ~3,786 tokens.

Download SKILL.mdSave it as .claude/skills/dart-rules/SKILL.md (or your agent's skills folder).
name
dart-rules
description
Dart/Flutter coding rules: style, patterns, security, testing. Triggers: .dart, pubspec.yaml, Flutter, Riverpod, Bloc, widget, StatelessWidget, StatefulWidget.
allowed-tools
Read
effort
medium
user-invocable
false

Dart/Flutter Rules

These rules come from app/rules/dart/ in ai-toolkit. They cover the project's standards for coding style, frameworks, patterns, security, and testing in Dart/Flutter. Apply them when writing or reviewing Dart/Flutter code.

Dart Coding Style

Naming

  • PascalCase: classes, enums, typedefs, extensions, mixins.
  • camelCase: variables, functions, methods, parameters, named constants.
  • snake_case: libraries, packages, directories, source files.
  • UPPER_SNAKE: not used in Dart. Use camelCase for constants.
  • Prefix private members with _: _internalState, _helper().

Null Safety

  • Enable sound null safety (default since Dart 2.12).
  • Use ? types only when null is semantically meaningful.
  • Use ! operator sparingly. Prefer null checks or ?? fallback.
  • Use late keyword only when initialization is guaranteed before access.
  • Use required keyword for mandatory named parameters.

Classes

  • Use const constructors for immutable classes.
  • Use factory constructors for caching, subtype selection, or validation.
  • Use named constructors for clarity: Point.fromJson(json).
  • Use final fields for immutable properties.
  • Use @immutable annotation on classes that should be immutable.

Functions

  • Use named parameters for functions with >2 parameters.
  • Use required for mandatory named parameters.
  • Use default values for optional parameters.
  • Use fat arrow (=>) for single-expression functions.
  • Always specify return types for public functions.

Collections

  • Use collection literals: [], {}, <String, int>{}.
  • Use if and for inside collection literals for conditional/iterative building.
  • Use spread operator: [...list1, ...list2].
  • Use whereType<T>() for type-safe filtering.
  • Prefer const collections when values are known at compile time.

Async

  • Use async/await for all asynchronous operations.
  • Return Future<T> from async functions. Never return void.
  • Use Stream<T> for continuous data (events, real-time updates).
  • Use Future.wait() for concurrent independent operations.
  • Use Completer<T> only when wrapping callback-based APIs.

Imports

  • Order: dart: SDK, package: external, relative project imports.
  • Use show/hide to limit import scope when names conflict.
  • Use as prefix for namespace conflicts: import 'package:foo/foo.dart' as foo.
  • Prefer relative imports within the same package.

Formatting

  • Use dart format (line length 80) for consistent formatting.
  • Use dart analyze for static analysis with default lint rules.
  • Use analysis_options.yaml with recommended lints: flutter_lints or lints.
  • Use trailing commas in multi-line argument lists for cleaner diffs.

Dart Frameworks

Flutter

  • Use StatelessWidget by default. Use StatefulWidget only for local state.
  • Use const constructors and const widgets for build optimization.
  • Use Key parameters for widgets in lists for correct diffing.
  • Extract large build() methods into smaller widget classes (not methods).
  • Use Theme.of(context) and TextTheme for consistent styling.

Navigation

  • Use GoRouter for declarative, type-safe routing.
  • Define routes as constants: static const String home = '/home'.
  • Use ShellRoute for persistent navigation bars across routes.
  • Use context.go() for navigation, context.push() for stacking.
  • Pass arguments via path parameters or extra for complex objects.

Networking

  • Use dio for HTTP with interceptors, retry, and cancellation.
  • Use retrofit (code gen) for type-safe REST client definitions.
  • Use interceptors for auth token injection and refresh logic.
  • Set timeouts on every request: connectTimeout, receiveTimeout.
  • Use CancelToken for cancelling in-flight requests on navigation.

JSON Serialization

  • Use json_serializable (+ build_runner) for generated fromJson/toJson. Default fieldRename: FieldRename.none uses Dart property names as-is — combined with Effective Dart lowerCamelCase, this produces camelCase JSON keys with zero configuration.
  • Flutter docs recommend: "best if both server and client follow the same naming strategy" (Flutter — JSON and serialization). When they do, no mapping is needed.
  • When server uses a different convention, prefer @JsonSerializable(fieldRename: FieldRename.snake) at the class level (or globally in build.yaml) over sprinkling @JsonKey(name:) on every field. Community recommendation from the json_serializable docs and pub.dev guides.
  • Use individual @JsonKey(name: '...') only for exceptional cases: external API with mixed conventions, reserved Dart keyword collision (class, is, new), or legacy field rename during deprecation window. Document the reason in a comment.
  • For enum / status / permission values on the wire: UPPER_SNAKE_CASE is the cross-language community consensus (see common/coding-style.md — JSON Wire Format Conventions). Dart enum case names themselves stay lowerCamelCase per Effective Dart; map them to uppercase strings in fromJson/toJson (value.toUpperCase() + switch).
  • Write unit tests asserting both directions (fromJson + toJson) with explicit expected keys. Catches contract drift at CI time.

Local Storage

  • Use shared_preferences for simple key-value persistence.
  • Use drift (formerly Moor) for type-safe SQLite with reactive queries.
  • Use hive for fast, lightweight NoSQL local storage.
  • Use flutter_secure_storage for sensitive data (tokens, passwords).
  • Never store secrets in shared_preferences (not encrypted).

Dependency Injection

  • Use get_it for service locator pattern. Register at app startup.
  • Use injectable (code gen) for automatic registration from annotations.
  • Use Riverpod providers as DI containers for testable architecture.
  • Register singletons for services, factories for per-use instances.

Platform Channels

  • Use MethodChannel for invoking native (iOS/Android) code.
  • Use EventChannel for streaming data from native to Dart.
  • Use Pigeon (code gen) for type-safe platform channel definitions.
  • Handle MissingPluginException gracefully on unsupported platforms.

Testing Frameworks

  • Use flutter_test for widget tests with WidgetTester.
  • Use integration_test package for full app integration tests.
  • Use patrol for native-aware integration testing (permissions, notifications).
  • Use golden_toolkit for advanced visual regression testing.

Build and CI

  • Use flutter build with --release and --dart-define for env configuration.
  • Use flavors (--flavor) for dev/staging/prod build variants.
  • Use flutter analyze in CI for static analysis enforcement.
  • Use flutter test --coverage with lcov for coverage reporting.

Dart Patterns

Error Handling

  • Use typed exceptions for domain errors: class UserNotFoundException implements Exception.
  • Use try-catch with specific exception types. Avoid bare catch (e).
  • Use rethrow to preserve stack trace when re-raising exceptions.
  • Use Result<T, E> pattern (e.g., dartz Either) for expected failures.
  • Use Future.catchError() only when async/await is not applicable.

State Management (Flutter)

  • Use Riverpod for compile-safe, testable state management.
  • Use BLoC pattern for event-driven state with clear input/output.
  • Use ChangeNotifier / ValueNotifier for simple local state.
  • Use StateNotifier (Riverpod) for immutable state transitions.
  • Keep state classes immutable. Use copyWith() for updates.

Riverpod

  • Use @riverpod annotation (code gen) for provider definitions.
  • Use ref.watch() for reactive dependencies. Use ref.read() for one-time access.
  • Use AsyncNotifier for async state management.
  • Use autoDispose for providers that should clean up when unused.
  • Use family modifier for parameterized providers.

BLoC Pattern

  • Separate events (input), states (output), and logic (bloc).
  • Use sealed class for events and states (exhaustive switch).
  • Use Emitter<State> for emitting state transitions.
  • Use transformEvents() for debouncing search inputs.
  • Use BlocObserver for global logging and error tracking.

Repository Pattern

  • Abstract data sources behind repository interfaces.
  • Repositories return domain models, not DTOs or raw data.
  • Use Future<T> for single values, Stream<T> for real-time updates.
  • Cache data in repository layer when appropriate.
  • Inject repositories via constructor. Use Riverpod/GetIt for DI.

Freezed (Code Generation)

  • Use @freezed for immutable data classes with copyWith, equality, toString.
  • Use @freezed sealed unions for state modeling: factory State.loading().
  • Use when() / map() for exhaustive pattern matching on freezed unions.
  • Run dart run build_runner build after modifying freezed classes.
Show full SKILL.md (695 more words)Show less

Async Patterns

  • Use Stream.asyncMap() for transforming streams with async operations.
  • Use StreamController<T> for custom streams. Close in dispose().
  • Use Completer<T> to bridge callback APIs to Future-based APIs.
  • Use Timer.periodic() for polling. Cancel in dispose().
  • Use compute() (Flutter) for CPU-intensive work on isolates.

Anti-Patterns

  • Using dynamic type: defeats type safety. Use Object? or generics.
  • Not disposing controllers/subscriptions: causes memory leaks.
  • Putting business logic in widgets: extract to services/blocs.
  • Using setState() for global state: use proper state management.
  • Deep widget nesting: extract sub-widgets as separate classes.

Dart Security

Input Validation

  • Validate all user input in form fields with TextFormField validators.
  • Use RegExp for pattern validation (email, phone, URL).
  • Sanitize HTML content before rendering. Never use Html widget with raw user input.
  • Validate deep link parameters before navigation or data loading.
  • Limit text input length with maxLength on TextFormField.

Network Security

  • Use HTTPS exclusively. Configure SecurityContext for certificate pinning.
  • Use dio interceptors for consistent auth header injection.
  • Validate SSL certificates in production. Do not disable certificate checks.
  • Set connection and read timeouts on all HTTP requests.
  • Use CancelToken to abort requests when the user navigates away.

Data Storage

  • Use flutter_secure_storage for tokens, passwords, and API keys.
  • Never store sensitive data in shared_preferences (stored in plaintext).
  • Encrypt local databases (drift with sqlcipher, or hive with encryption).
  • Clear secure storage on user logout.
  • Use kIsWeb checks to handle web platform storage limitations.

Authentication

  • Use OAuth 2.0 / OIDC with PKCE flow for mobile authentication.
  • Store refresh tokens in secure storage. Store access tokens in memory.
  • Use flutter_appauth for standards-compliant OAuth flows.
  • Implement biometric authentication with local_auth package.
  • Never store credentials in Dart source code or asset files.

Platform Channel Security

  • Validate all data received from native code via platform channels.
  • Do not pass sensitive data through MethodChannel logging-enabled calls.
  • Use Pigeon for type-safe channel communication (prevents mismatched types).
  • Handle PlatformException gracefully for missing native implementations.

Obfuscation and Hardening

  • Use --obfuscate --split-debug-info=<dir> for release builds.
  • Use --dart-define for environment-specific configuration (not secrets).
  • Do not embed API keys in the Dart source. Use server-side proxying.
  • Use ProGuard rules (Android) and symbol stripping (iOS) for native code.

WebView Security

  • Use webview_flutter with JavaScript disabled unless explicitly needed.
  • Restrict navigation to allowlisted domains with NavigationDelegate.
  • Sanitize any data passed from WebView to Dart via JavaScript channels.
  • Do not load untrusted URLs in WebViews.

Dependency Security

  • Run dart pub outdated regularly. Update dependencies promptly.
  • Audit pubspec.lock for unexpected transitive dependencies.
  • Use dart pub audit (when available) for vulnerability scanning.
  • Prefer well-maintained packages with high pub.dev scores.
  • Pin exact versions in pubspec.yaml for production apps.

Dart Testing

Framework

  • Use package:test for pure Dart unit tests.
  • Use package:flutter_test for Flutter widget and integration tests.
  • Use package:mockito with @GenerateMocks for mock generation.
  • Use package:mocktail as a simpler alternative (no code generation).

File Naming

  • Test files: foo_test.dart in test/ mirroring lib/ structure.
  • Widget tests: test/widgets/ for Flutter widget tests.
  • Integration tests: integration_test/ directory (Flutter convention).
  • Golden tests: test/goldens/ for visual regression snapshots.

Structure

  • Use group() for organizing related tests.
  • Use setUp() / tearDown() for per-test setup and cleanup.
  • Use setUpAll() / tearDownAll() for expensive one-time setup.
  • Name tests descriptively: test('returns null when user is not found', ...).

Assertions

  • Use expect(actual, matcher) with built-in matchers.
  • Use equals(), isNull, isNotNull, isA<T>() for type/value checks.
  • Use throwsA(isA<FormatException>()) for exception testing.
  • Use completion(expected) for Future assertions.
  • Use emitsInOrder([...]) for Stream emission testing.

Mocking (Mockito)

  • Annotate: @GenerateMocks([UserRepository]). Run build_runner.
  • Stub: when(mock.getUser(any)).thenAnswer((_) async => user).
  • Verify: verify(mock.saveUser(captureAny)).called(1).
  • Use verifyNever() to assert a method was not called.
  • Use throwOnMissingStub() to catch unstubbed method calls.

Widget Testing (Flutter)

  • Use testWidgets('description', (tester) async { ... }).
  • Use tester.pumpWidget(MaterialApp(home: MyWidget())) to render.
  • Use tester.pump() to trigger rebuilds after state changes.
  • Use tester.pumpAndSettle() to wait for animations to complete.
  • Use find.byType(), find.text(), find.byKey() for widget lookups.
  • Use tester.tap(), tester.enterText() for interaction simulation.

Golden Tests

  • Use matchesGoldenFile('goldens/my_widget.png') for visual comparison.
  • Run flutter test --update-goldens to regenerate baseline images.
  • Use golden tests for complex UI components, not simple widgets.
  • Keep golden tests platform-specific (render output varies by OS).

Best Practices

  • Test public API behavior, not implementation details.
  • Use fake classes (implementing interfaces) for simple test doubles.
  • Use addTearDown() to register cleanup in the test body.
  • Run flutter test --coverage and check coverage/lcov.info.
  • Use blocTest() from bloc_test package for BLoC testing.

© softspark, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in app/skills/dart-rules of softspark/ai-toolkit.

Open the folder on GitHubat commit d64db2b

Compare with similar skills

Dart Rules next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Dart Rules compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Dart Rules this skillsoftspark/ai-toolkit179—~3.8kAutomated safety check: PassApache-2.0
Engine Whats Newflutter/flutter179k—~978Automated safety check: PassBSD-3-Clause
Flutter Cherry Pickflutter/flutter179k—~1.8kAutomated safety check: PassBSD-3-Clause
Upgrade Browserflutter/flutter179k—~1.1kAutomated safety check: PassBSD-3-Clause
Bump Dartflutter/flutter179k—~1.2kAutomated safety check: PassBSD-3-Clause
Run Devicelab With Ledflutter/flutter179k—~786Automated safety check: PassBSD-3-Clause

Similar skills

  • Engine Whats New

    flutter/flutter

    Generates the "what's new" release summary and diff file for changes in the Flutter engine (//engine/src/flutter) between two releases (e.g., 3.47 vs 3.44).

    179k GitHub stars~978 tokensUpdated today
    MobileAuto-check passed
  • Flutter Cherry Pick

    flutter/flutter

    How to land a formal cherry-pick of a merged PR for the flutter/flutter repo stable or beta channel.

    179k GitHub stars~1.8k tokensUpdated today
    MobileAuto-check passed
  • Upgrade Browser

    flutter/flutter

    Upgrade browser versions (Chrome or Firefox) in the Flutter Web Engine and/or Framework tests.

    179k GitHub stars~1.1k tokensUpdated today
    MobileAuto-check passed
  • Bump Dart

    flutter/flutter

    Do not trigger automatically; only run when a user runs /bump-dart.

    179k GitHub stars~1.2k tokensUpdated today
    MobileAuto-check passed
  • Run Devicelab With Led

    flutter/flutter

    Run DeviceLab tests for Flutter PRs using LUCI's led CLI tool.

    179k GitHub stars~786 tokensUpdated today
    MobileAuto-check passed
  • Shepherd PRs

    flutter/flutter

    Automate shepherding, checking status, updating branches, and landing open PRs or approved third-party contributor PRs in the flutter/flutter repository using the gh CLI.

    179k GitHub stars~1.7k tokensUpdated today
    MobileAuto-check passed

More from softspark/ai-toolkit

All 112 skills in this repo
  • Prepare Test Env

    softspark/ai-toolkit

    Prepare or verify a project QA environment with source identity, readiness, browser access, evidence paths and owned cleanup.

    179 GitHub stars~1.8k tokensUpdated yesterday
    Auto-check: notes
  • A11y Validate

    softspark/ai-toolkit

    Accessibility validator: WCAG 2.1 AA, EN 301 549, EAA. An agent skill from softspark/ai-toolkit.

    179 GitHub stars~3.8k tokensUpdated yesterday
    Auto-check: notes
  • Analyze

    softspark/ai-toolkit

    Analyzes code quality, complexity, patterns across codebase.

    179 GitHub stars~1k tokensUpdated yesterday
    Auto-check passed
  • Autonomous Dev

    softspark/ai-toolkit

    Drives a brief, specification, issue or existing PR through implementation, review, tests and QA to a ready PR.

    179 GitHub stars~2.6k tokensUpdated yesterday
    Auto-check: notes
  • Brand Voice

    softspark/ai-toolkit

    Direct technical voice for docs, README, user-facing text. An agent skill from softspark/ai-toolkit.

    179 GitHub stars~2.1k tokensUpdated yesterday
    Auto-check passed
  • CI

    softspark/ai-toolkit

    Detect/generate/debug CI pipeline config (GitHub Actions, GitLab CI).

    179 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check: notes

Works with

Categories

Questions about Dart Rules

What does Dart Rules do?

Dart/Flutter coding rules: style, patterns, security, testing. Dart Rules is an agent skill from softspark/ai-toolkit. Dart/Flutter coding rules: style, patterns, security, testing.

When should I use Dart Rules?

Dart Rules fits situations like: tasks that involve Cross-platform mobile apps.

How do I install Dart Rules in Claude Code?

Run `npx skills add softspark/ai-toolkit --skill dart-rules -a claude-code`. Or copy the skill folder (app/skills/dart-rules in softspark/ai-toolkit) into .claude/skills/dart-rules in your project. Claude Code loads it when a task matches its description.

How do I install Dart Rules in Codex?

Run `npx skills add softspark/ai-toolkit --skill dart-rules -a codex`. Or copy the skill folder (app/skills/dart-rules in softspark/ai-toolkit) into .agents/skills/dart-rules in your project. Codex loads it when a task matches its description.

Can I use Dart Rules in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add softspark/ai-toolkit --skill dart-rules -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/dart-rules, .gemini/skills/dart-rules, .github/skills/dart-rules and .opencode/skills/dart-rules in your project.

What does Dart Rules need to run?

Going by SKILL.md and its folder, Dart Rules needs the command-line tools its instructions call (dart and flutter). Its frontmatter pre-approves these tools: Read.

Does Dart Rules access the network?

SKILL.md names 1 domain. As links in the text: docs.flutter.dev. This is read from the text; nothing was executed.

Is Dart Rules safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Dart Rules use?

Dart Rules is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Dart Rules use?

About 3.8k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Dart Rules?

Skills that share tags, products or a category with Dart Rules: Engine Whats New (flutter/flutter, 179k stars), Flutter Cherry Pick (flutter/flutter, 179k stars), Upgrade Browser (flutter/flutter, 179k stars) and Bump Dart (flutter/flutter, 179k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Dart Rules?

softspark (a GitHub user) maintains it in softspark/ai-toolkit, which has 179 GitHub stars. The repository holds 112 skills in this directory. The repository was last updated on October 7, 2026.

Source: softspark/ai-toolkit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.