wind dynamic.instructions.md

Instructions for a Flutter renderer that builds app interfaces from JSON descriptions. Flutter is a framework for creating mobile, web, and desktop apps from Dart code.

In plain words
What is it for?
Use it to render JSON-defined widget trees, connect widget values to state, handle JSON actions, and add approved custom widgets or icons.
Why use it?
It defines which widgets JSON may create, how values are stored, and how actions such as navigation are passed to the app, while limiting unapproved widget types.

Instructions file for GitHub Copilot

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/fluttersdk/wind/dynamic
Clone the repo
git clone --depth 1 https://github.com/fluttersdk/wind

Made for: GitHub Copilot.

Per session 1,267 This file is loaded in full into every session.
When invoked 1,267 The same file — it is already loaded in full.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.01267 $0.01267
Opus 5 $0.00633 $0.00633
Sonnet 5 $0.00253 $0.00253
Haiku 4.5 $0.00127 $0.00127

Measured yesterday against content hash 3e91bfaa589e, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

wind dynamic.instructions.md scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

.github/instructions/dynamic.instructions.md · 98 lines

How it starts

The opening of the file, as written. The whole thing — 98 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Dynamic JSON renderer (lib/src/dynamic/)

WDynamic renders Flutter widget trees from JSON. Pieces:

  • WDynamic — the StatefulWidget consumers use. Composes the other parts.
  • WDynamicConfig — security + customization (denyWidgets, builders, customIcons, maxDepth, callbacks).
  • WDynamicState — id-keyed value store + listeners (ChangeNotifier).
  • WDynamicController — wraps external state; tracks _ownsState to gate disposal.
  • WActionHandler — bridges JSON actions to Dart callbacks; handles _value injection.
  • WDynamicRenderer — the dispatch loop; one giant switch over type strings.

JSON schema

{
  "type": "WText",
  "props": {
    "text": "Hello",
    "className": "text-lg",
    "id": "greeting",
    "onTap": {"action": "navigate", "args": {"route": "/home"}}
  },
  "children": [...]
}
  • type (String, REQUIRED) — must be in the whitelist (defaultWindWidgetsdefaultFlutterWidgetsconfig.builders.keys) and not in denyWidgets.
  • props (Map, optional) — widget-specific. className, id, action props, and per-widget config live here.
  • children (List, optional) — nested widget definitions.

Security model (whitelist first)

Order of resolution in WDynamicConfig.isAllowed(type):

  1. config.builders[type] — custom builder always wins.
  2. config.denyWidgets.contains(type) — explicit block; emits error widget.
  3. Default whitelist (13 Wind widgets + 16 Flutter core).

Untrusted JSON: pass denyWidgets for surfaces a remote source must not invoke (e.g., 'Container' if you don't trust raw boxes). Always set maxDepth (default 50) — recursion bomb mitigation.

State binding (id-keyed widgets)

WInput, WCheckbox, WSelect, WDatePicker with props.id read initial value from state.get(id) and write back on change. Reactive: same id from another widget triggers a rebuild via WDynamicState's addIdListener.

External vs internal state ownership:

  • WDynamic(controller: WDynamicController())_ownsState = false; the host owns disposal.
  • WDynamic(...) no controller — _ownsState = true; WDynamic creates the state and disposes it.

Read the full file on GitHub · 98 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 98 lines · 1,267 tokens per session scan A 3e91bfaa589e

Subscribe to this mod's changes

wind dynamic.instructions.md is an instructions file published in the GitHub repository fluttersdk/wind (33 stars, last pushed 2d ago), licensed MIT. It adds 1,267 tokens to every session, about $0.0063 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other instructions, from other repositories

mobile CLAUDE.md

Claude Code instructions for lichess-org/mobile, covering claude.md, project overview, development setup, initial setup and install dependencies.

lichess-org/mobile · 4,362 tokens

dart_agent_core AGENTS.md

Instructions for memex-lab/dart_agent_core, covering agents.md, common commands, transcript viewer cli (reads eval traces), two public libraries and architecture (big picture).

memex-lab/dart_agent_core · 1,450 tokens

sanad-agent AGENTS.md

Instructions for EastStarAI/sanad-agent, covering sanad agent repository contract, 1. documentation hierarchy, rules for ai agents and developers, 1.1. the strict separation pact and 1.2. the living project wiki & incremental documentation.

EastStarAI/sanad-agent · 3,115 tokens

terradart CLAUDE.md

Instructions for nozomi-koborinai/terradart: Use AGENTS.md as the shared project guide. Read CONTEXT.md for project vocabulary before design work.

nozomi-koborinai/terradart · 63 tokens

dart-sdk-skills AGENTS.md

Instructions for RandalSchwartz/dart-sdk-skills, covering ai agent developer handbook (agents.md), 🎯 repository purpose, 🔄 runbook 1: updating for new dart sdk releases, 🔄 runbook 2: updating for new flutter framework releases and 📏 quality & style guidelines.

RandalSchwartz/dart-sdk-skills · 736 tokens

dart-expert-skills copilot-instructions.md

Instructions for Poorgramer-Zack/dart-expert-skills, covering flutter skills repository - copilot instructions, repository overview, architecture, directory structure and skill structure.

Poorgramer-Zack/dart-expert-skills · 2,008 tokens