firebase-development:add-feature
Fail
Audited by Gen Agent Trust Hub on Feb 15, 2026
Risk Level: HIGHPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION] (HIGH): The skill is vulnerable to indirect prompt injection (Category 8) because it processes potentially untrusted codebase data and has high-privilege execution capabilities.\n
- Ingestion points: The skill uses
lsandgrepin Step 2 to explore project files, and it readspackage.json,firestore.rules, and other source files throughout the workflow.\n - Boundary markers: No boundary markers (delimiters) or 'ignore embedded instructions' warnings are present to protect the agent from instructions hidden in the code.\n
- Capability inventory: The skill executes several powerful shell commands, including
npm run test,npm run build, andfirebase emulators:start.\n - Sanitization: There is no evidence of sanitization or content validation for data read from the local file system before it influences the agent's actions.\n- [COMMAND_EXECUTION] (MEDIUM): The skill utilizes several subprocess calls to manage the development lifecycle. While standard for its purpose, these commands enable the execution of local scripts which could be manipulated by an attacker who has modified the project configuration (e.g., the
testscript inpackage.json).
Recommendations
- AI detected serious security threats
Audit Metadata