firebase
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from multiple external sources that could potentially contain malicious instructions for the AI agent.
- Ingestion points: Data enters through Firestore documents (e.g., users, posts), Cloud Storage object metadata, and Firebase Authentication user profiles.
- Boundary markers: No specific delimiters or ignore instructions are provided to separate user-provided data from agent instructions.
- Capability inventory: The agent has permissions to perform database writes and administrative auth actions via the Firebase Admin SDK.
- Sanitization: The skill relies on Firestore Security Rules for data validation, which do not protect the prompt context from indirect injection.
- [EXTERNAL_DOWNLOADS]: The skill specifies the installation of official firebase, firebase-admin, and firebase-tools packages from the standard NPM registry. These are well-known resources provided by Google for Firebase development and are utilized correctly within the context of the skill.
Audit Metadata