firebase
Pass
Audited by Gen Agent Trust Hub on Jul 1, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references the installation of official tools including
firebase-toolsfrom NPM and theflutterfire_clifrom pub.dev. These are well-known tools from a trusted organization (Google/Firebase) and are used for their intended configuration purposes. - [COMMAND_EXECUTION]: The instructions utilize standard CLI commands such as
flutterfire configure,dart pub, andflutter pubto manage project configuration and dependencies, which is appropriate for a development-focused skill. - [SAFE]: No malicious patterns, obfuscation, or unauthorized data access attempts were detected. The skill actively promotes security best practices, such as replacing 'test mode' rules with ownership-based authorization and using App Check for client attestation.
- [CREDENTIALS_UNSAFE]: The skill provides accurate guidance regarding Firebase configuration files (e.g.,
google-services.json), noting that while they should be kept out of public repositories, they contain public identifiers rather than sensitive private keys.
Audit Metadata