extension-to-functions-codebase
Pass
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides purely instructional content and architectural patterns for refactoring Firebase codebases without executing unauthorized commands.
- [SAFE]: Secure configuration management is prioritized through the use of official SDK features like defineSecret and defineJsonSecret for handling sensitive data.
- [SAFE]: The skill includes an explicit defensive instruction to prevent the agent from performing sensitive actions, specifically stating 'NEVER execute npm publish'.
- [SAFE]: The migration guide encourages declarative IAM security via requiresRole and requiresAPI, which helps implement the principle of least privilege.
- [SAFE]: References to external dependencies (firebase-admin and firebase-functions) involve well-known, official libraries from a trusted vendor.
Audit Metadata