setup-firebase-hosting

Warn

Audited by Socket on Aug 19, 2026

1 alert found:

Anomaly
AnomalyLOW
scripts/bootstrap-firebase.sh

No direct evidence of sabotage/malware (e.g., reverse shell, hidden backdoor, obfuscated payloads, or exfiltration to non-Google domains) is present in the provided fragment. The code is a legitimate-but-sensitive provisioning/CI bootstrap flow: it creates/rotates GCP service account keys and uploads the key to a GitHub Secret for deployment. The main security concern is the high impact of credential handling; if the script or its inputs are compromised, service account keys could be exposed via the GitHub Secret sink. Overall: likely benign automation with sensitive side effects; further review of the full repository/script (especially helper functions and any earlier/later code not shown) is recommended.

Confidence: 62%Severity: 55%
Audit Metadata
Analyzed At
Aug 19, 2026, 02:45 PM
Package URL
pkg:socket/skills-sh/fandhe-ai%2Fagent-cli-skills%2Fsetup-firebase-hosting%2F@e3f1fdc2357665a8d5591616817180939e4edd3365a4adf5d97b27c0b2a85ae7
Security Audit — socket — setup-firebase-hosting