firestore

Pass

Audited by Gen Agent Trust Hub on Jul 6, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's functionality is consistent with its stated purpose. It promotes secure practices such as least-privilege rules, transaction usage for invariants, and not trusting client-side fields.\n- [EXTERNAL_DOWNLOADS]: The skill mentions the firebase/agent-skills companion skill. This is a reference to a well-known service and official infrastructure associated with the Firebase platform.\n- [COMMAND_EXECUTION]: Provides standard commands for validation using the Firebase CLI (firebase emulators), Node.js (npm test), and the Android build system (gradlew). These are static, purpose-appropriate commands for the developer workflow.\n- [PROMPT_INJECTION]: The skill possesses a functional attack surface for indirect prompt injection as it is designed to analyze project-specific code and configuration files.\n
  • Ingestion points: Analyzes firestore.rules, database.rules.json, and Firebase index configurations from the project workspace.\n
  • Boundary markers: No explicit boundary markers or instruction-isolation delimiters are defined in the workflow.\n
  • Capability inventory: The skill suggests code modifications and executes build/test commands (firebase, gradlew, npm).\n
  • Sanitization: No explicit sanitization or filtering of ingested file content is mentioned, relying on the agent's default safety guardrails.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 6, 2026, 12:31 PM
Security Audit — agent-trust-hub — firestore