firebase-app-check

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFE
Full Analysis
  • [CREDENTIALS_UNSAFE]: No hardcoded credentials or sensitive secrets were found. The skill correctly instructs the user to use environment variables (process.env.EXPO_PUBLIC_APP_CHECK_DEBUG_TOKEN, process.env.NEXT_PUBLIC_RECAPTCHA_SITE_KEY) for configuration, which is a standard and safe practice for client-side keys and tokens.
  • [EXTERNAL_DOWNLOADS]: The skill references standard, official packages from the Firebase and React Native Firebase ecosystems (@react-native-firebase/app-check, firebase/app-check). These are well-known libraries from trusted sources.
  • [PROMPT_INJECTION]: No patterns of prompt injection, role-play overrides, or instructions to bypass safety guidelines were detected in the skill markdown or references.
  • [OBFUSCATION]: The content is written in clear, plain text. No instances of Base64 encoding, zero-width characters, homoglyphs, or other obfuscation techniques were identified.
  • [DATA_EXFILTRATION]: There are no commands or code snippets that attempt to access sensitive system files or exfiltrate data to unauthorized external domains.
  • [PERSISTENCE]: The skill does not attempt to establish persistence on the host system through shell profiles, cron jobs, or startup scripts.
  • [DYNAMIC_CONTEXT_INJECTION]: The skill does not use the dynamic context injection syntax (!command) to execute shell commands at load time.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 05:42 PM
Security Audit — agent-trust-hub — firebase-app-check