firebase-development:project-setup
Audited by Socket on Feb 16, 2026
1 alert found:
Malware[Skill Scanner] Installation of third-party script detected All findings: [CRITICAL] command_injection: Installation of third-party script detected (SC006) [AITech 9.1.4] [HIGH] data_exfiltration: Credential file access detected (DE002) [AITech 8.2.3] BENIGN / Low-risk guidance content. This skill is a scaffolding/instruction document for initializing Firebase projects. It does not contain malicious code or hidden exfiltration. The main security consideration is operational: ensure .env and credential files are properly gitignored and never committed, and verify any service account keys are stored and rotated according to policy. Follow standard best practices when installing global CLIs and adding API keys. LLM verification: Selected report 1 provides the most thorough and structured assessment of the Firebase project-setup skill and offers a clear, practical workflow. The content is benign with respect to malicious activity; potential concerns (e.g., hardcoded emulator port and environment file handling) are manageable with standard development hygiene. A modest security risk remains due to local emulator exposure and environment file handling, but no immediate threat is identified.