firebase-app-check

Warn

Audited by Socket on Sep 12, 2026

1 alert found:

Anomaly
AnomalyLOW
references/debug-tokens.md

No malware or intentional data theft is present. This is security guidance for Firebase App Check debug-token workflows. Debug tokens are bearer credentials that bypass attestation, so exposing them or enabling the debug provider in production would create a significant backend access risk. The CI example should be reviewed because an EXPO_PUBLIC_ variable may be embedded in client-visible artifacts by some tooling.

Confidence: 99%Severity: 58%
Audit Metadata
Analyzed At
Sep 12, 2026, 05:43 PM
Package URL
pkg:socket/skills-sh/dentvega%2Ffirebase-agent-skills%2Ffirebase-app-check%2F@f3535e8fd891ce6cef1af5dcb50b0b55dd484797f25a2b50a9655ce28fb2e140
Security Audit — socket — firebase-app-check