Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/joker-x-dev/flutterkit/fkit-datanpx skills add Joker-x-dev/FlutterKit --skill fkit-datagit clone --depth 1 https://github.com/Joker-x-dev/FlutterKitWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00064 | $0.00563 |
| Opus 5 | $0.00032 | $0.00282 |
| Sonnet 5 | $0.00013 | $0.00113 |
| Haiku 4.5 | $0.00006 | $0.00056 |
Grade A, and why
fkit-data scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
FKit Data
必读资料
先阅读 AGENTS.md,再根据数据来源读取:
- 总体边界:
docs/flutter-kit/框架核心/data.md - 模型:
docs/flutter-kit/框架核心/model.md - 网络:
docs/flutter-kit/框架核心/network.md、docs/flutter-kit/框架核心/result.md - 数据库:
docs/flutter-kit/框架核心/database.md - 键值存储:
docs/flutter-kit/框架核心/datastore.md - 全局状态:
docs/flutter-kit/框架核心/state.md - 页面状态机:对应
docs/flutter-kit/框架核心/base-network.md、docs/flutter-kit/框架核心/base-list.md或docs/flutter-kit/框架核心/base-refresh.md
选择数据链路
- 网络:Model → Network DataSource → Repository →
RequestHelper或网络父类 → Logic/State。 - SQLite:Database Entity/Provider → Local DataSource → Repository → Logic/Service。
- 键值存储:Store DataSource → Store Repository → Logic/Service。
- 长期状态:Repository 恢复持久化数据 → Core Service 维护跨模块状态。
Feature 只能依赖 Repository 或 Service,不直接依赖具体 DataSource 实现。
工作流
- 从真实契约确定 Entity、Request、Response、可空性、成功码和分页字段。
- 复用现有基础模型和数据源结构,保持接口、实现和 Repository 单一职责。
- 使用完整领域名声明 Repository 字段,不使用
_repository。 - 网络结果交给
RequestHelper或网络父类统一处理;不要在 Logic 重复制造复杂 try/catch、Toast 和 loading 生命周期。 - 页面展示状态写入 Feature State;持久化状态通过 Repository/DataSource;跨模块长期状态才进入 Core Service。
- 修改注解或 Retrofit 声明后运行代码生成,不手工修改
*.g.dart。
验证
为 DataSource、Repository、Result 或 Service 补充成功、业务失败、异常、空值和分页边界测试。运行代码生成、相关测试、静态分析和 git diff --check,确认 Feature 未绕过 Repository。
What ships with it
1 file beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 41 lines · 64 tokens per session scan A c8756fbc5ec2
fkit-data is a skill published in the GitHub repository Joker-x-dev/FlutterKit (110 stars, last pushed 1mo ago), licensed MIT. It adds 64 tokens to every session and 563 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
orca-emulator-android
Control an Android emulator / device from inside Orca using the orca CLI. Use for listing/booting AVDs, taps, swipes, typing, hardware buttons (incl. Back and Recents), rotation, app install/launch, runtime permissions, the accessibility tree, and logcat — driving a real adb-connected device or emulator.…
android-tombstone-symbolication
Symbolicate the .NET runtime frames in an Android tombstone file. Extracts BuildIds and PC offsets from the native backtrace, downloads debug symbols from the Microsoft symbol server, and runs llvm-symbolizer to produce function names with source file and line numbers. USE FOR triaging a .NET MAUI or Mono Android app…
git-safety
Git safety rules. INVOKE WHEN: git push, force push, git reset, git clean, destructive git, push force, reset hard. NEVER force push or do destructive git operations.
dogfood
Systematically explore and test a mobile app on iOS/Android with agent-device to find bugs, UX issues, and other problems. Use when asked to dogfood, QA, exploratory test, find issues, bug hunt, or test this app on mobile.
release
Cut a sim-use release end-to-end. Use when the user runs /release or asks to "ship a release", "publish a version", "cut a release", or "release to homebrew". Drives scripts/local-release.sh; never reimplement its build/sign/tarball logic.
android-pentest
安卓应用渗透测试 — APK分析、Hook、自动化测试、运行态驱动、签名恢复、抓包分析.