Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsCommunityBlog
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Flutter Ci Cd

ASecurity

Create, repair, or harden provider-neutral Flutter CI/CD pipelines, quality gates, caches, artifacts, secrets, and staged delivery. Use for GitHub Actions, GitLab CI, Codemagic, Bitrise, Xcode Cloud, or similar orchestration; route local artifact configuration to flutter-build-release and never publish without explicit authorization.

7 stars
0 votes
0 copies
0 views
Added 9/19/2026
ai-agentsrustgotestinggitci/cdsecurity

Security Analysis

A100/100

Scanned 9/19/2026

Install to Claude Code

$npx -y skills add thiennc-tesoglobal/flutter-skills --skill flutter-ci-cd --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Flutter Ci Cd?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Flutter Ci Cd
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/thiennc-tesoglobal-flutter-ci-cd/badge)](https://www.skillsdirectory.com/skills/thiennc-tesoglobal-flutter-ci-cd)

More formats (shields.io, HTML) on the badges page.

Download with Pro
Files
SKILL.md
---
name: flutter-ci-cd
description: Create, repair, or harden provider-neutral Flutter CI/CD pipelines, quality gates, caches, artifacts, secrets, and staged delivery. Use for GitHub Actions, GitLab CI, Codemagic, Bitrise, Xcode Cloud, or similar orchestration; route local artifact configuration to flutter-build-release and never publish without explicit authorization.
---

# Flutter CI/CD

Build a reproducible pipeline around the repository's existing delivery model. Preserve the current provider, Flutter version source, package manager, flavors, signing flow, and deployment tooling unless migration is explicitly requested.

## Preflight

Read `pubspec.yaml`, lockfiles, SDK/version-manager files, workspace layout, generated-code policy, flavors, tests, native targets, existing pipeline files, repository scripts, release tooling, protected environments, and secret names before writing pipeline changes. Inspect the actual job dependency graph and recent timing/failure output when diagnosing reliability or speed. When repository evidence is unavailable, request or list the exact files and logs required and keep advice at the invariant level; do not present a placeholder workflow as a completed repair. Never print, move, synthesize, or commit signing material or service credentials.

Separate pull-request confidence from release authority. A passing CI job may prove checks and artifact creation; it does not authorize tagging, store upload, production deployment, or credential changes.

## Route the work

- For deterministic format, analysis, generation, test, coverage, golden, matrix, and cache gates, read [quality gates](references/quality-gates.md).
- For signing, secrets, artifacts, symbols, protected environments, staged rollout, and publication boundaries, read [delivery and secrets](references/delivery-and-secrets.md).
- For GitHub Actions, GitLab CI, Codemagic, Bitrise, Xcode Cloud, monorepos, and provider-preserving decisions, read [provider and monorepo](references/provider-and-monorepo.md).

Load only the references needed by the current pipeline.

## Boundaries

- `flutter-build-release` owns flavors, signing configuration, versioning, symbol production, and local store-ready artifacts; inspect and orchestrate those established commands instead of reimplementing them inside provider YAML.
- `flutter-testing` owns test strategy and test implementation; this skill runs the repository's chosen suites as gates.
- `flutter-security` owns a broader security audit; this skill still applies least privilege, secret isolation, trusted dependency pinning, and untrusted-fork boundaries.
- Do not change application architecture, state management, or packages to make pipeline authoring more convenient.

## Verification

Validate provider syntax with the provider's current linter/dry-run facility and run every underlying repository command locally where the environment permits. Check cold and cached paths, pull-request and protected-branch conditions, expected artifacts, cancellation/concurrency behavior, and failure propagation. A cache hit and miss must produce the same correctness result. Formatting and golden gates must not rewrite source or expectations. A freshness gate may run the established generator in the disposable checkout, but it must fail on a resulting diff and must never commit or conceal that diff. For delivery, prefer a dry run or non-production target before any authorized external mutation.

Report commands and pipeline paths changed, environments exercised, artifact evidence, and any macOS runner, signing, secret, quota, or store-side gap. Never weaken a gate merely to turn the pipeline green.

## Sources

- [Continuous delivery with Flutter](https://docs.flutter.dev/deployment/cd)
- [Testing Flutter apps](https://docs.flutter.dev/testing/overview)
- [GitHub Actions security guidance](https://docs.github.com/en/code-security/tutorials/secure-your-organization/protect-against-threats)

Attribution

thiennc-tesoglobalthiennc-tesoglobal
View sourceMore from thiennc-tesoglobal →
SSkills DirectorySkills Directory

Know which skills are safe — weekly.

Best new skills + every skill we flagged as malicious. From the team that scanned 103,619.

Join free

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Know which skills are safe — weekly.

Best new skills + every skill we flagged as malicious. From the team that scanned 103,619.

Join free

Related Skills

Caveman

Ultra-compressed communication mode that cuts output tokens while keeping technical accuracy. Levels: lite, full, ultra and the wenyan variants. Use for /caveman, "caveman mode", "talk like caveman", "be brief" or "less tokens".

1074701 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

693161 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3351 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

691 votes

math-skill

A comprehensive mathematical reasoning skill for AI assistants — handles arithmetic to research-level problems with rigorous step-by-step reasoning, systematic verification, and transparent uncertainty handling

381 votes
View all in ai-agents →