AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified Apache-2.0 Self-run

Stream Flutter

skill-getstream-agent-skills-stream-flutter · by GetStream

Build and integrate Stream Chat, Video, and Feeds in Flutter apps. Use for Flutter/Dart project work with Stream package setup, auth wiring, and widget blueprints. Supports stream_chat_flutter (pre-built Chat UI), stream_chat_flutter_core (custom Chat UI), stream_video_flutter (Video calling and livestreaming), and stream_feed / stream_feed_flutter_core (Activity Feeds, no pre-built UI).

No reviews yet
0 installs
4 views
0.0% view→install

Install

$ agentstack add skill-getstream-agent-skills-stream-flutter

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-getstream-agent-skills-stream-flutter)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
1mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Stream Flutter? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Stream Flutter - skill router + execution flow

Rules: Read [RULES.md](RULES.md) once per session - every non-negotiable rule is stated there, nowhere else.

This file is the single entrypoint: intent classification, local project detection, and module pointers for Stream work in Flutter apps.


Step 0: Intent classifier (mandatory first - never skip)

Before any tool call, decide the track from the user's input alone - no probes first.

Signals -> track

| Signal in user input | Track | | ------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------- | | Explicit package/widget token: stream_chat_flutter, StreamChannelListView, StreamMessageListView, StreamChatClient, etc. | C - Reference lookup | | Explicit video token: stream_video_flutter, StreamCallContainer, StreamVideo, StreamVideoRenderer, goLive, stopLive, livestream call type | C - Reference lookup | | Explicit feeds token: stream_feed, stream_feed_flutter_core, StreamFeedClient, FlatFeedCore, FlatFeed, FeedBloc, activity feed, feeds flutter | C - Reference lookup | | Words "docs" or "documentation" around Stream Flutter work | C - Reference lookup | | "How do I {X} in Flutter?", "What does {widget/method} do?" | C - Reference lookup | | "Build me a new Flutter app", "create a Flutter chat app" + Stream | A - New app | | "Build a Flutter video call app", "create a livestream app in Flutter" | A - New app (load VIDEO-FLUTTER.md + VIDEO-FLUTTER-blueprints.md or LIVESTREAM-FLUTTER.md + LIVESTREAM-FLUTTER-blueprints.md) | | "Build an audio room / Twitter Spaces clone", "TikTok-style live feed", "call while livestreaming", "chat with video calls", "two calls at once" | A or B (load VIDEO-ADVANCED-FLUTTER.md + VIDEO-ADVANCED-FLUTTER-blueprints.md on top of the Video/Livestream pair) | | "Add ringing / incoming calls", "video call with push notifications", "CallKit", "VoIP push", "FCM ringing", "missed call notification" | A or B (load RINGING-FLUTTER.md + RINGING-FLUTTER-blueprints.md on top of the Video pair) | | "Build a Flutter feeds app", "create an activity feed app", "build a social feed in Flutter", "create a Twitter/Instagram clone" | A - New app (load FEEDS-FLUTTER.md + FEEDS-FLUTTER-blueprints.md; use Twitter-style UI unless the user explicitly specifies otherwise) | | "Add/integrate Stream into this app", "wire Chat into my Flutter project" | B - Existing app | | "Add video calling to my Flutter app", "integrate Stream Video into my existing app" | B - Existing app (load VIDEO-FLUTTER.md + VIDEO-FLUTTER-blueprints.md) | | "Add a feed to my Flutter app", "integrate Stream Feeds into my existing app", "add activity feed" | B - Existing app (load FEEDS-FLUTTER.md + FEEDS-FLUTTER-blueprints.md; use Twitter-style UI unless the user explicitly specifies otherwise) | | "Install Stream packages", "set up Stream in Flutter", "wire auth/token" with no broader feature request | D - Bootstrap / setup | | Bare /stream-flutter with no args | List the tracks briefly and wait |

Disambiguation flow

If the request is ambiguous between build/integrate and reference lookup, ask one short question and wait:

> Do you want me to wire this into the project, or just map the Flutter SDK pattern and widgets?

After classification

  • Tracks A, B, D -> run Project signals once per session, then continue in [builder.md](builder.md) and [sdk.md](sdk.md).
  • Track C -> skip the probe if the product + package are explicit. Only run it on demand if the SDK layer is ambiguous.

Step 0.5: Credentials, token, and seed data (tracks A, B, D only)

Run this once per session, right after intent classification, before the Project signals probe.

Goal

Collect the Stream API key, a user token, and optionally seed channels or calls - all before touching code - so the app has real data to show from the first run.

Single upfront question (ask exactly once, then act immediately)

Post one message asking all relevant things together. Do not split into multiple rounds.

For Chat projects:

> To wire everything up with real data, I need a few quick answers: > > 1. Credentials - Should I fetch your API key from the dashboard and generate a token via the Stream CLI, or will you paste them yourself? > 2. Token expiry - If I'm generating the token: should it expire? (e.g. 1h, 1d, 30m) or never expire? > 3. Seed channels - Should I pre-create a few channels with random usernames so the app has something to show immediately? > > If you want to handle everything yourself, just paste your API key and token and tell me whether to seed channels.

For Video projects (calls are ephemeral - no seeding needed):

> To wire everything up, I need a couple of quick answers: > > 1. Credentials - Should I fetch your API key from the dashboard and generate a token via the Stream CLI, or will you paste them yourself? > 2. Token expiry - If I'm generating the token: should it expire? (e.g. 1h, 1d, 30m) or never expire? > > If you want to handle everything yourself, just paste your API key and token.

> Guest-viewer requirement — surface this BEFORE building any app that signs viewers in as guests. A guest connects with the guest role, which by default has minimal capabilities. On the livestream call type guests cannot even read or join a call until the integrator grants those capabilities to the guest role. When a guest-based viewer flow is in scope, tell the integrator it is a prerequisite to grant the guest role read-call and join-call (plus create-call if a viewer may open the call before the host) on the relevant call type via Stream Dashboard → Video & Audio → Call Types → → Roles & Permissions (or the API), or to use authenticated User.regular viewers instead. Details: [references/VIDEO-FLUTTER.md](references/VIDEO-FLUTTER.md) → Guest users, and [references/LIVESTREAM-FLUTTER.md](references/LIVESTREAM-FLUTTER.md) → Roles, permissions, and backstage security.

For Feeds projects (no pre-built UI; feed groups required):

Ask one message with all setup questions together — do not split into rounds:

> To wire everything up, I need a few quick answers: > > 1. Credentials - Should I fetch your API key from the dashboard and generate a token via the Stream CLI, or will you paste them yourself? > 2. Token expiry - If I'm generating the token: should it expire? (e.g. 1h, 1d, 30m) or never expire? > 3. Feed groups - I need to create 3 feed groups in your Stream project (user, timeline, notification). Should I set these up automatically, or have you already created them? > 4. Seed posts - Should I add a few sample posts so the feed has content from the first run? > > If you want to handle credentials yourself, just paste your API key and token.

Once the user replies, execute all steps without pausing. For feed groups, if the user said "set up automatically":

getstream api CreateFeedGroup --request '{"id": "user", "type": "flat"}'
getstream api CreateFeedGroup --request '{"id": "timeline", "type": "flat"}'
getstream api CreateFeedGroup --request '{"id": "notification", "type": "notification"}'

If the CLI commands fail (the Feeds API may use different endpoints than Chat), tell the user once:

> Please create these in Stream Dashboard → Activity Feeds → Feed Groups: user (Flat), timeline (Flat), notification (Notification).

For Feeds projects, always generate two separate helpers in main after connect():

  1. _setupFollows(client)always called, unconditionally. Makes timeline follow user so the user's own posts appear there. Do not merge this into seed logic — once seed data exists the guard returns early and the follow call never runs.
  2. _seedPosts(client) — only if the user said yes to seeding. Adds sample activities and exits early if data already exists.

See [references/FEEDS-FLUTTER.md](references/FEEDS-FLUTTER.md) for both implementations.

The package is stream_feeds: ^0.5.1 — not the deprecated stream_feed or stream_feed_flutter_core.

After the user replies - act without further prompting

Once the user answers, execute all CLI steps in sequence without pausing for confirmation between them. Narrate each step briefly as you go (one line per action), but do not stop to ask "shall I continue?".

Step A - API key
getstream env --target flutter

This writes the public API key to dart_defines.json; the app reads it via String.fromEnvironment('STREAM_API_KEY') and is run with flutter run --dart-define-from-file=dart_defines.json. If the command returns a 401 error, the CLI session has expired - run getstream login to re-authenticate, then retry.

If getstream is not installed (command not found): ask the user to install it from https://getstream.io and wait. Or, if the user prefers, skip the CLI entirely and have them paste the API key + a token per user (Dashboard -> Explorer has a token generator). Decide based on the user's answer to the upfront credentials question; don't stall.

Step B - Token
# Never-expiring
getstream token 

# Expiring
getstream token  --ttl 

Hold the token in context. Use it (and the API key) in every code snippet - no placeholder strings.

Step C - Seed channels (only if the user said yes)

Create 3-5 channels with random realistic usernames. Use messaging as the default channel type.

Sub-step C1 — upsert all users (seed users + the token user):

getstream api UpdateUsers --request '{
  "users": {
    "": {"id": "", "name": ""},
    "alice": {"id": "alice", "name": "Alice"},
    "bob":   {"id": "bob",   "name": "Bob"},
    "carol": {"id": "carol", "name": "Carol"},
    "dave":  {"id": "dave",  "name": "Dave"}
  }
}'

Sub-step C2 — create each channel (no members in the body; members are added in C3):

getstream api GetOrCreateChannel --type messaging --id  \
  --request '{"data": {"name": ""}}'

Repeat for each channel (e.g. general, random, team-alpha).

Sub-step C3 — add members to each channel using add_members. The token user must be in every channel so the Filter.in_('members', [userId]) query in the app returns results.

getstream api UpdateChannel --type messaging --id  \
  --request '{
    "add_members": [
      {"user_id": ""},
      {"user_id": "alice"},
      {"user_id": "bob"}
    ],
    "user_id": ""
  }'

Generate short memorable channel IDs (e.g. general, random, team-alpha) and use a small set of random usernames (e.g. alice, bob, carol, dave). The token user must be added to every channel — the channel list filter is Filter.in_('members', [tokenUserId]) and will return nothing if the user is absent.

After seeding, print a brief summary:

> Created channels: general (tokenuser, alice, bob), random (tokenuser, carol, dave), team-alpha (token_user, alice, carol)

Step D - Proceed automatically

After all CLI steps succeed, move straight to Project signals and then into builder.md - no additional prompt needed. If any CLI step fails, explain the error briefly and ask the user to paste the missing value manually before continuing.

What NOT to do

  • Never put the API secret in app code - the CLI uses it server-side only.
  • Never invent or fabricate credentials.
  • Never ask "should I continue?" between Step A, B, C, and D - execute the whole sequence once the user's upfront answers are in.

Permissions awareness (Chat - surface proactively)

Stream Chat checks permissions per role, per scope on every client-side call — but server-side calls (the CLI and your backend, using the API secret) bypass all checks. That asymmetry is the #1 source of "it worked when you seeded it, but the app 403s": seeding channels via the CLI succeeds regardless of grants, then the same query/join from the app hits the connected user's role and fails.

When the app you're about to build does anything beyond chatting inside channels the user is already a member of, tell the integrator about the relevant grants before writing the feature — don't wait for a runtime 403. Map the scenario to the grant:

| App behaviour you're building | Grant the connecting role needs on the channel type | Default messaging for user/guest | | ------------------------------------------------------------------------------------------------ | -------------------------------------------------------------- | -------------------------------------- | | Discover / browse groups the user didn't create (queryChannels without a members filter) | Read Channel (ReadChannel) | often off | | Join an existing group (channel.addMembers([myId])) | Add Own Channel Membership (AddOwnChannelMembership) | often off | | Leave a group (channel.removeMembers([myId])) | `Remove Own Chan

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.