firebase-storage
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides patterns for handling user-controlled data, specifically file paths and binary blobs.
- Ingestion points: Untrusted data enters the agent context through
request.data.pathin the Cloud Function example (SKILL.md) and via file URIs obtained fromexpo-image-picker(references/expo-image-picker.md). - Boundary markers: The instructions demonstrate anchoring paths to user identities (e.g.,
users/${uid}/avatar.jpg) and using Firebase Security Rules to enforce ownership. - Capability inventory: The skill facilitates file uploads (
putFile,uploadBytes), bucket provisioning via CLI, security rule deployment, and signed URL generation. - Sanitization: The Cloud Function example includes a manual authorization check ensuring the path starts with the user's UID (
path.startsWith("users/${request.auth.uid}/")). - [COMMAND_EXECUTION]: The skill utilizes standard command-line tools for environment setup and project management.
- Includes usage of the Firebase CLI (
firebase-tools) vianpxfor listing buckets, initializing storage, and deploying rules. - Utilizes
gsutilfor Google Cloud Storage bucket management. - Uses
npx expo installfor managing React Native dependencies. - [EXTERNAL_DOWNLOADS]: The skill references and installs several standard libraries from well-known ecosystems.
- Downloads the official Firebase CLI (
firebase-tools) from the npm registry. - Installs official Expo and React Native Firebase packages (e.g.,
@react-native-firebase/storage,expo-image-picker).
Audit Metadata