firebase

Pass

Audited by Gen Agent Trust Hub on Jul 1, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references the installation of official tools including firebase-tools from NPM and the flutterfire_cli from pub.dev. These are well-known tools from a trusted organization (Google/Firebase) and are used for their intended configuration purposes.
  • [COMMAND_EXECUTION]: The instructions utilize standard CLI commands such as flutterfire configure, dart pub, and flutter pub to manage project configuration and dependencies, which is appropriate for a development-focused skill.
  • [SAFE]: No malicious patterns, obfuscation, or unauthorized data access attempts were detected. The skill actively promotes security best practices, such as replacing 'test mode' rules with ownership-based authorization and using App Check for client attestation.
  • [CREDENTIALS_UNSAFE]: The skill provides accurate guidance regarding Firebase configuration files (e.g., google-services.json), noting that while they should be kept out of public repositories, they contain public identifiers rather than sensitive private keys.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 1, 2026, 10:33 AM
Security Audit — agent-trust-hub — firebase