firebase-development:project-setup

Fail

Audited by Gen Agent Trust Hub on Feb 16, 2026

Risk Level: HIGHCOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION] (HIGH): The skill is susceptible to Indirect Prompt Injection (Category 8) due to its interaction model. • Ingestion Point: User responses gathered via 'AskUserQuestion' regarding architecture decisions. • Boundary Markers: Absent. There are no delimiters or instructions to ignore instructions embedded in user data. • Capability Inventory: High-privilege actions including shell execution ('firebase init', 'npm install', 'git init') and file system writes ('firebase.json', 'firestore.rules', 'index.ts'). • Sanitization: Absent. Input is used to drive logic for scaffolding the project structure and configuration.
  • [COMMAND_EXECUTION] (HIGH): The workflow executes various shell commands in the user's environment, including global package installation and project initialization. This provides an attacker-controlled input path to powerful system capabilities.
  • [EXTERNAL_DOWNLOADS] (LOW): Installs 'firebase-tools' and various development dependencies via npm. Per [TRUST-SCOPE-RULE], these are downgraded to LOW as they originate from reputable sources (Google), though the execution of these tools remains a high-capability operation.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Feb 16, 2026, 11:10 AM
Security Audit — agent-trust-hub — firebase-development:project-setup