skills/ericrisco/rsc-harness/firebase/Gen Agent Trust Hub

firebase

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides high-quality educational content and defensive patterns for Firebase development. It explicitly warns against anti-patterns like hardcoded secrets and open security rules.
  • [COMMAND_EXECUTION]: The scripts/verify.sh script is provided to audit local Firebase configuration files. It utilizes standard Unix utilities (find, grep, sed) and well-known interpreters (node, python3) to perform read-only linting and JSON validation. These operations are performed locally and serve a clear, documented defensive purpose.
  • [DATA_EXFILTRATION]: No network exfiltration or credential harvesting patterns were found. The skill emphasizes using environment secrets and warns against committing service account keys to source control.
  • [PROMPT_INJECTION]: The skill instructions are consistent with the stated purpose and do not attempt to override agent safety guidelines or manipulate agent behavior beyond the Firebase domain.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 09:36 PM
Security Audit — agent-trust-hub — firebase