firebase-development:validate

Fail

Audited by Gen Agent Trust Hub on Feb 16, 2026

Risk Level: HIGHCOMMAND_EXECUTION
Full Analysis
  • [Indirect Prompt Injection] (HIGH): The skill processes untrusted external project files and possesses significant execution capabilities.
  • Ingestion points: Processes firebase.json, package.json, and all TypeScript files within the functions/src/ directory.
  • Boundary markers: None present. The skill does not implement delimiters or warnings to ignore embedded instructions in the codebase it audits.
  • Capability inventory: Executes npm test, npm run test:coverage, npm audit, and npm run build. These commands trigger scripts defined in the project's package.json.
  • Sanitization: No sanitization or validation of the project's configuration files before execution.
  • [Command Execution] (MEDIUM): The skill invokes shell commands (grep, npm) to validate the project state. While these are standard development tasks, executing scripts from a codebase currently under security review is inherently risky, as the codebase itself may be the attack vector.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Feb 16, 2026, 12:04 PM
Security Audit — agent-trust-hub — firebase-development:validate