firebase-development:debug
Fail
Audited by Gen Agent Trust Hub on Feb 16, 2026
Risk Level: HIGHCREDENTIALS_UNSAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE] (HIGH): The skill explicitly directs the agent to access and read sensitive environment files in Step 6 (
cat functions/.env,cat hosting/.env.local) and Step 7 (cat firebase.json,cat .firebaserc). It also suggests logging 'API key' values in Step 5, which risks exposing secrets in the agent's session or history logs. - [PROMPT_INJECTION] (HIGH): The skill is highly vulnerable to Indirect Prompt Injection (Category 8).
- Ingestion points: The agent reads untrusted data from
firebase-debug.log, emulator terminal output, and Firestore data structures during debugging workflows. - Boundary markers: There are no defined delimiters or instructions to treat log/error data as untrusted, increasing the risk of the agent obeying instructions embedded within error messages.
- Capability inventory: The skill possesses significant capabilities including process termination (
kill -9), script execution (npm run build), and environment file access (cat .env). - Sanitization: No sanitization or validation of the log content is performed. An attacker could trigger a specific application error containing malicious instructions that the agent would then execute.
- [COMMAND_EXECUTION] (MEDIUM): The skill utilizes powerful command-line operations such as
kill -9 <PID>andnpm run build. While these are part of a standard developer workflow, their presence combined with the lack of input validation for PIDs or build scripts poses a risk of misuse or accidental system disruption.
Recommendations
- AI detected serious security threats
Audit Metadata