firebase-cli

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references the official Firebase installation URL (https://firebase.tools) within documentation and error messages as a suggested installation method.
  • [COMMAND_EXECUTION]: The skill executes the 'firebase' command through a perl-based timeout wrapper in its self-test scripts to prevent hanging sessions.
  • [INDIRECT_PROMPT_INJECTION]: The skill acts as a gatekeeper for user-provided Firebase commands. 1. Ingestion points: Command strings are passed to the scripts/firebase_risk.py classifier. 2. Boundary markers: The skill enforces a multi-tier safety model (Safe, Write, Destructive, Forbidden) requiring human confirmation for any mutation. 3. Capability inventory: The skill allows execution of the full Firebase CLI toolset after classification. 4. Sanitization: The classifier uses the shlex library to securely parse shell command segments and handle quoting appropriately.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 10:39 AM
Security Audit — agent-trust-hub — firebase-cli