firebase
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides high-quality educational content and defensive patterns for Firebase development. It explicitly warns against anti-patterns like hardcoded secrets and open security rules.
- [COMMAND_EXECUTION]: The
scripts/verify.shscript is provided to audit local Firebase configuration files. It utilizes standard Unix utilities (find,grep,sed) and well-known interpreters (node,python3) to perform read-only linting and JSON validation. These operations are performed locally and serve a clear, documented defensive purpose. - [DATA_EXFILTRATION]: No network exfiltration or credential harvesting patterns were found. The skill emphasizes using environment secrets and warns against committing service account keys to source control.
- [PROMPT_INJECTION]: The skill instructions are consistent with the stated purpose and do not attempt to override agent safety guidelines or manipulate agent behavior beyond the Firebase domain.
Audit Metadata