firestore
Pass
Audited by Gen Agent Trust Hub on Jul 6, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill's functionality is consistent with its stated purpose. It promotes secure practices such as least-privilege rules, transaction usage for invariants, and not trusting client-side fields.\n- [EXTERNAL_DOWNLOADS]: The skill mentions the
firebase/agent-skillscompanion skill. This is a reference to a well-known service and official infrastructure associated with the Firebase platform.\n- [COMMAND_EXECUTION]: Provides standard commands for validation using the Firebase CLI (firebase emulators), Node.js (npm test), and the Android build system (gradlew). These are static, purpose-appropriate commands for the developer workflow.\n- [PROMPT_INJECTION]: The skill possesses a functional attack surface for indirect prompt injection as it is designed to analyze project-specific code and configuration files.\n - Ingestion points: Analyzes
firestore.rules,database.rules.json, and Firebase index configurations from the project workspace.\n - Boundary markers: No explicit boundary markers or instruction-isolation delimiters are defined in the workflow.\n
- Capability inventory: The skill suggests code modifications and executes build/test commands (
firebase,gradlew,npm).\n - Sanitization: No explicit sanitization or filtering of ingested file content is mentioned, relying on the agent's default safety guardrails.
Audit Metadata