firebase-dynamic-ports-setup

Pass

Audited by Gen Agent Trust Hub on Apr 30, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The script examples/kill-firebase-ports.js utilizes child_process.spawn to execute the kill-port utility. The implementation includes robust sanitization by filtering input ports to ensure they are valid numbers before execution, effectively preventing command injection vulnerabilities.
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the download and execution of the kill-port package from the NPM registry via npx. This is a standard developer practice for managing local network resources and is used here for its intended purpose of clearing port conflicts.
  • [SAFE]: The skill promotes secure development habits by instructing users to gitignore sensitive local configuration files (.env, firebase.local.json) and recommending the use of demo- prefixes for Firebase projects to ensure the emulator remains isolated from live production services.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 30, 2026, 02:59 AM
Security Audit — agent-trust-hub — firebase-dynamic-ports-setup