firebase-development:project-setup
Fail
Audited by Gen Agent Trust Hub on Feb 16, 2026
Risk Level: HIGHCOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION] (HIGH): The skill is susceptible to Indirect Prompt Injection (Category 8) due to its interaction model. • Ingestion Point: User responses gathered via 'AskUserQuestion' regarding architecture decisions. • Boundary Markers: Absent. There are no delimiters or instructions to ignore instructions embedded in user data. • Capability Inventory: High-privilege actions including shell execution ('firebase init', 'npm install', 'git init') and file system writes ('firebase.json', 'firestore.rules', 'index.ts'). • Sanitization: Absent. Input is used to drive logic for scaffolding the project structure and configuration.
- [COMMAND_EXECUTION] (HIGH): The workflow executes various shell commands in the user's environment, including global package installation and project initialization. This provides an attacker-controlled input path to powerful system capabilities.
- [EXTERNAL_DOWNLOADS] (LOW): Installs 'firebase-tools' and various development dependencies via npm. Per [TRUST-SCOPE-RULE], these are downgraded to LOW as they originate from reputable sources (Google), though the execution of these tools remains a high-capability operation.
Recommendations
- AI detected serious security threats
Audit Metadata