原始内容
Flutter Claude Skills
A collection of specialized Claude Code skills for Flutter development, focusing on testing and security best practices.
What are Claude Skills?
Claude Code is Anthropic's official CLI tool that brings Claude AI directly to your terminal. Skills are modular capabilities that extend Claude's functionality for specific domains or tasks. Each skill consists of a SKILL.md file with instructions, plus optional supporting files like scripts and templates.
Skills are model-invoked - Claude autonomously decides when to activate them based on your request and the skill's description. You don't need to explicitly call a skill; simply describe what you want to do, and Claude will activate the relevant skill automatically.
Available Skills
1. Flutter Tester
Name: flutter-tester
Purpose: Comprehensive testing guidance for Flutter applications
A specialized skill that provides expert guidance on creating, writing, and analyzing tests in Flutter projects. Covers unit tests, widget tests, integration tests, and provides deep knowledge of mocking patterns, Riverpod state management testing, and industry best practices.
Key Features:
- Given-When-Then test structure patterns
- Layer-by-layer testing strategies (Repository, DAO, Service, Provider, Widget)
- Mockito and Riverpod testing patterns
- Widget testing with proper screen size setup and key usage
- Database testing with FakeDatabase
- Stream, timer, and async testing patterns
- Quick reference table mapping scenarios to patterns
- Common mistakes guide covering the most frequent testing pitfalls
- Comprehensive test checklists and verification patterns
Reference Documentation:
- Layer testing patterns (repositories, providers, DAOs)
- Widget testing guide with interaction patterns
- Riverpod testing guide for state management
2. OWASP Mobile Security Checker
Name: owasp-mobile-security-checker
Purpose: Security analysis and vulnerability assessment for Flutter mobile applications
A comprehensive security auditing skill based on the OWASP Mobile Top 10 (2024) guidelines. Combines automated Python scanning scripts with detailed manual analysis workflows to identify vulnerabilities, assess security posture, and provide actionable remediation guidance.
Key Features:
Automated Scanners:
- M1: Hardcoded secrets and credential detection
- M2: Dependency security and outdated package analysis (with safe FVM detection via
shutil.which) - M5: Network security validation (HTTPS, certificate pinning)
- M9: Storage security analysis (encryption, secure storage)
Manual Analysis Guidance:
- M3: Authentication and authorization patterns
- M4: Input/output validation strategies
- M6: Privacy controls and PII handling
- M7: Binary protections and obfuscation
- M8: Security misconfiguration detection
- M10: Cryptography implementation review
Comprehensive Reporting:
- Severity-based prioritization (CRITICAL → HIGH → MEDIUM → LOW)
- Flutter-specific code examples
- Actionable remediation steps
- OWASP risk categorization
Scope guidance: built for Flutter/mobile — not for web, backend, or as a substitute for professional pentesting
Reference Documentation:
- OWASP Mobile Top 10 (2024) detailed guide
- Flutter-specific vulnerability patterns
- Secure vs insecure code examples
Installation
Prerequisites
- Claude Code installed and configured
- For OWASP Security Checker: Python 3.7+
Setup Options
Option 1: npx skills (Recommended)
Install globally across all your projects with a single command:
npx skills add Harishwarrior/flutter-claude-skills

To install for the current project only:
npx skills add Harishwarrior/flutter-claude-skills --agent claude-code
Option 2: Personal Skills (Manual)
Install to ~/.claude/skills/ for use across all your projects:
cd ~/.claude/skills/
git clone https://github.com/Harishwarrior/flutter-claude-skills.git
After cloning, the skills will be available in:
~/.claude/skills/flutter-claude-skills/flutter-tester/~/.claude/skills/flutter-claude-skills/owasp-mobile-security-checker/
Option 3: Project Skills (Recommended for team use)
Install to .claude/skills/ in your Flutter project for team sharing:
cd /path/to/your/flutter/project
mkdir -p .claude/skills
cd .claude/skills
git clone https://github.com/Harishwarrior/flutter-claude-skills.git
Commit the .claude/skills/ directory to git so team members automatically get the skills when they pull.
Note: Claude automatically discovers skills from both locations. No additional configuration needed.
Usage
Skills are automatically activated by Claude based on your request. You don't need to explicitly invoke them - just describe what you want to do naturally.
Flutter Tester - Example Requests
Claude will automatically activate the flutter-tester skill when you work on Flutter tests:
# In your Flutter project directory
claude
Example conversations:
"Help me write widget tests for my LoginScreen"
→ Claude detects you need testing help and activates flutter-tester
"Create unit tests for my UserRepository class"
→ Automatically uses flutter-tester patterns
"My widget tests in auth_screen_test.dart are failing. Can you help debug them?"
→ Claude applies flutter-tester debugging guidelines
"How should I test Riverpod providers?"
→ Provides Riverpod testing patterns from the skill
"Review my test coverage and suggest missing test cases"
→ Uses flutter-tester checklist and best practices
OWASP Mobile Security Checker - Example Requests
Claude will automatically activate the owasp-mobile-security-checker skill for security-related requests:
For automated scanning:
"Check my Flutter app for hardcoded secrets and API keys"
→ Claude runs scan_hardcoded_secrets.py
"Scan my dependencies for security vulnerabilities"
→ Claude runs check_dependencies.py
"Verify my app uses HTTPS and has proper certificate pinning"
→ Claude runs check_network_security.py
"Analyze my app's data storage for security issues"
→ Claude runs analyze_storage_security.py
"Perform a comprehensive OWASP security audit"
→ Claude runs all scanners and performs manual analysis
For manual analysis:
"Review my authentication implementation for security issues"
→ Claude applies M3 (Authentication) guidelines
"Check my app for input validation vulnerabilities"
→ Claude applies M4 (Input Validation) patterns
"Audit my cryptography implementation"
→ Claude applies M10 (Cryptography) best practices
Running Scanners Manually
You can also run the security scanners directly:
# Set the skill directory path (adjust if you used Option 2 / project install)
SKILL_DIR=~/.claude/skills/flutter-claude-skills/owasp-mobile-security-checker
# From your Flutter project root
cd /path/to/your/flutter/project
# Run individual scanners
python3 $SKILL_DIR/scripts/scan_hardcoded_secrets.py .
python3 $SKILL_DIR/scripts/check_dependencies.py .
python3 $SKILL_DIR/scripts/check_network_security.py .
python3 $SKILL_DIR/scripts/analyze_storage_security.py .
Results are saved as JSON files in your project directory.
Skill Details
Flutter Tester Structure
flutter-tester/
├── SKILL.md # Main skill definition and guidance
└── references/
├── layer_testing_patterns.md # Repository, Provider, DAO testing patterns
├── widget_testing_guide.md # Widget interaction and UI testing
└── riverpod_testing_guide.md # State management testing with Riverpod
OWASP Mobile Security Checker Structure
owasp-mobile-security-checker/
├── SKILL.md # Main skill definition and workflows
├── scripts/
│ ├── scan_hardcoded_secrets.py # M1: Credential scanning
│ ├── check_dependencies.py # M2: Package security
│ ├── check_network_security.py # M5: Network config validation
│ └── analyze_storage_security.py # M9: Storage security analysis
└── references/
└── owasp_mobile_top_10_2024.md # Complete OWASP guide with examples
Contributing
Contributions are welcome! Here's how you can help:
- Report issues - Found a bug or have a suggestion? Open an issue
- Improve patterns - Have a better testing or security pattern? Submit a PR
- Add examples - More real-world examples are always helpful
- Update scanners - Help keep the security scanners current with new patterns
- Documentation - Improve guides, add clarifications, fix typos
Contribution Guidelines
- Follow the existing structure and formatting
- Test your changes thoroughly
- Update relevant documentation
- Add examples where appropriate
- Keep security scanner patterns up-to-date with latest threats
Resources
Flutter Testing
Mobile Security
- OWASP Mobile Top 10 (2024)
- Flutter Security Best Practices
- Android Security Guidelines
- iOS Security Guide
Claude Code
License
This project is licensed under the MIT License - see the LICENSE file for details.
Support
- Issues: GitHub Issues
- Discussions: GitHub Discussions
Acknowledgments
- Built for Claude Code by Anthropic
- Testing patterns based on Flutter community best practices
- Security guidelines based on OWASP Mobile Top 10 (2024)
- Inspired by the Flutter and mobile security communities