firebase-app-check
Warn
Audited by Socket on Sep 12, 2026
1 alert found:
AnomalyAnomalyreferences/debug-tokens.md
LOWAnomalyLOW
references/debug-tokens.md
No malware or intentional data theft is present. This is security guidance for Firebase App Check debug-token workflows. Debug tokens are bearer credentials that bypass attestation, so exposing them or enabling the debug provider in production would create a significant backend access risk. The CI example should be reviewed because an EXPO_PUBLIC_ variable may be embedded in client-visible artifacts by some tooling.
Confidence: 99%Severity: 58%
Audit Metadata