firebase-storage

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides patterns for handling user-controlled data, specifically file paths and binary blobs.
  • Ingestion points: Untrusted data enters the agent context through request.data.path in the Cloud Function example (SKILL.md) and via file URIs obtained from expo-image-picker (references/expo-image-picker.md).
  • Boundary markers: The instructions demonstrate anchoring paths to user identities (e.g., users/${uid}/avatar.jpg) and using Firebase Security Rules to enforce ownership.
  • Capability inventory: The skill facilitates file uploads (putFile, uploadBytes), bucket provisioning via CLI, security rule deployment, and signed URL generation.
  • Sanitization: The Cloud Function example includes a manual authorization check ensuring the path starts with the user's UID (path.startsWith("users/${request.auth.uid}/")).
  • [COMMAND_EXECUTION]: The skill utilizes standard command-line tools for environment setup and project management.
  • Includes usage of the Firebase CLI (firebase-tools) via npx for listing buckets, initializing storage, and deploying rules.
  • Utilizes gsutil for Google Cloud Storage bucket management.
  • Uses npx expo install for managing React Native dependencies.
  • [EXTERNAL_DOWNLOADS]: The skill references and installs several standard libraries from well-known ecosystems.
  • Downloads the official Firebase CLI (firebase-tools) from the npm registry.
  • Installs official Expo and React Native Firebase packages (e.g., @react-native-firebase/storage, expo-image-picker).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 05:42 PM
Security Audit — agent-trust-hub — firebase-storage