firebase-cloud-functions
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill utilizes
npxto download and execute the latest version of the officialfirebase-toolspackage. This is a standard practice for using the Firebase CLI and targets a well-known, trusted service (Google/Firebase). - [COMMAND_EXECUTION]: The skill guides the execution of various Firebase CLI commands for project initialization (
init), deployment (deploy), and local emulation (emulators:start). These are routine development operations. - [DYNAMIC_EXECUTION]: The skill invokes a local scaffolding script (
node_modules/firebase-agent-skills/scripts/scaffold/callable-function.mjs) to generate boilerplate code for new functions. This is a common pattern for developer productivity tools and the script is treated as a vendor-specific resource for this skill set. - [SAFE]: The skill actively promotes security best practices, such as warning against hardcoding credentials, providing instructions for Secret Manager, and including mandatory authentication checks in code examples.
Audit Metadata