firebase-development:add-feature

Fail

Audited by Gen Agent Trust Hub on Feb 15, 2026

Risk Level: HIGHPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION] (HIGH): The skill is vulnerable to indirect prompt injection (Category 8) because it processes potentially untrusted codebase data and has high-privilege execution capabilities.\n
  • Ingestion points: The skill uses ls and grep in Step 2 to explore project files, and it reads package.json, firestore.rules, and other source files throughout the workflow.\n
  • Boundary markers: No boundary markers (delimiters) or 'ignore embedded instructions' warnings are present to protect the agent from instructions hidden in the code.\n
  • Capability inventory: The skill executes several powerful shell commands, including npm run test, npm run build, and firebase emulators:start.\n
  • Sanitization: There is no evidence of sanitization or content validation for data read from the local file system before it influences the agent's actions.\n- [COMMAND_EXECUTION] (MEDIUM): The skill utilizes several subprocess calls to manage the development lifecycle. While standard for its purpose, these commands enable the execution of local scripts which could be manipulated by an attacker who has modified the project configuration (e.g., the test script in package.json).
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Feb 15, 2026, 10:45 PM
Security Audit — agent-trust-hub — firebase-development:add-feature