firebase-docs

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill acts as a documentation routing aid for Firebase services. It consists of instructional text and a reference map of links, with no executable code, shell commands, or obfuscated content.
  • [EXTERNAL_DOWNLOADS]: The skill references the official documentation site firebase.google.com. These links target a well-known service and are used as trusted sources for information.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user queries and retrieves external documentation (ingestion points). It instructs the agent to use grounding phrases like 'According to Firebase docs' (boundary markers). The skill lacks dangerous tools like subprocess calls or file-write capabilities (capability inventory). While it does not implement technical sanitization of documentation content, the strict output framing serves as a logical guardrail (sanitization).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 11:52 AM
Security Audit — agent-trust-hub — firebase-docs