firebase-cli
Audited by Socket on Sep 6, 2026
1 alert found:
SecurityNo clear indicators of covert malware (exfiltration, backdoor/persistence, or stealthy payload execution) are present in this fragment. The dominant risk is supply-chain/control-plane misuse: the script is a Firebase administrative capability harness with high-impact delete/secret-destroy command presence and a reliance on an external $RISK classifier and potentially file-driven deletion targets. If $RISK or environment controls are tampered with, the same mechanism could enable destructive actions against real Firebase projects. Treat as high operational security risk; verify policy enforcement, permissions scoping, and integrity of the external classifier and any input files used for deletion targets.