firebase-cloud-functions

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill utilizes npx to download and execute the latest version of the official firebase-tools package. This is a standard practice for using the Firebase CLI and targets a well-known, trusted service (Google/Firebase).
  • [COMMAND_EXECUTION]: The skill guides the execution of various Firebase CLI commands for project initialization (init), deployment (deploy), and local emulation (emulators:start). These are routine development operations.
  • [DYNAMIC_EXECUTION]: The skill invokes a local scaffolding script (node_modules/firebase-agent-skills/scripts/scaffold/callable-function.mjs) to generate boilerplate code for new functions. This is a common pattern for developer productivity tools and the script is treated as a vendor-specific resource for this skill set.
  • [SAFE]: The skill actively promotes security best practices, such as warning against hardcoding credentials, providing instructions for Secret Manager, and including mandatory authentication checks in code examples.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 05:42 PM
Security Audit — agent-trust-hub — firebase-cloud-functions