firebase-realtime-database

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches the Firebase CLI (firebase-tools) and official SDKs (@react-native-firebase/database, firebase) from the public NPM registry.
  • [COMMAND_EXECUTION]: Invokes the Firebase CLI via npx for project initialization, deployment of security rules, and starting the local emulator.
  • [INDIRECT_PROMPT_INJECTION]:
  • Ingestion points: Data is received from Firebase Realtime Database listeners (.on('value')) in SKILL.md.
  • Boundary markers: Not present in the client-side UI code snippets.
  • Capability inventory: Perform database writes, updates, and presence state management via the Firebase SDK.
  • Sanitization: Demonstrates the use of server-side .validate rules in database.rules.json to enforce data types, children presence, and string length limits.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 05:42 PM
Security Audit — agent-trust-hub — firebase-realtime-database