firebase-cli

Warn

Audited by Socket on Sep 6, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/self_test.sh

No clear indicators of covert malware (exfiltration, backdoor/persistence, or stealthy payload execution) are present in this fragment. The dominant risk is supply-chain/control-plane misuse: the script is a Firebase administrative capability harness with high-impact delete/secret-destroy command presence and a reliance on an external $RISK classifier and potentially file-driven deletion targets. If $RISK or environment controls are tampered with, the same mechanism could enable destructive actions against real Firebase projects. Treat as high operational security risk; verify policy enforcement, permissions scoping, and integrity of the external classifier and any input files used for deletion targets.

Confidence: 50%Severity: 75%
Audit Metadata
Analyzed At
Sep 6, 2026, 10:40 AM
Package URL
pkg:socket/skills-sh/georgekhananaev%2Fclaude-skills-vault%2Ffirebase-cli%2F@40ec48c43a77788c6348aeef520048e649384b01e87012d96c097b2c16079390
Security Audit — socket — firebase-cli