firebase-app-check
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFE
Full Analysis
- [CREDENTIALS_UNSAFE]: No hardcoded credentials or sensitive secrets were found. The skill correctly instructs the user to use environment variables (
process.env.EXPO_PUBLIC_APP_CHECK_DEBUG_TOKEN,process.env.NEXT_PUBLIC_RECAPTCHA_SITE_KEY) for configuration, which is a standard and safe practice for client-side keys and tokens. - [EXTERNAL_DOWNLOADS]: The skill references standard, official packages from the Firebase and React Native Firebase ecosystems (
@react-native-firebase/app-check,firebase/app-check). These are well-known libraries from trusted sources. - [PROMPT_INJECTION]: No patterns of prompt injection, role-play overrides, or instructions to bypass safety guidelines were detected in the skill markdown or references.
- [OBFUSCATION]: The content is written in clear, plain text. No instances of Base64 encoding, zero-width characters, homoglyphs, or other obfuscation techniques were identified.
- [DATA_EXFILTRATION]: There are no commands or code snippets that attempt to access sensitive system files or exfiltrate data to unauthorized external domains.
- [PERSISTENCE]: The skill does not attempt to establish persistence on the host system through shell profiles, cron jobs, or startup scripts.
- [DYNAMIC_CONTEXT_INJECTION]: The skill does not use the dynamic context injection syntax (
!command) to execute shell commands at load time.
Audit Metadata