firebase

Warn

Audited by Socket on Sep 8, 2026

1 alert found:

Security
SecurityMEDIUM
references/firestore-database.md

No malicious or obfuscated code is present. The principal risk is an insecure Firestore ruleset: broad `allow write` validation rules are ORed with authorization rules and can permit unauthenticated or unauthorized writes to users and posts. Public user reads expose email and other profile data. Restrict writes to authenticated owners/admins, validate immutable and permitted fields explicitly, protect role and authorId, and avoid public reads of sensitive user data.

Confidence: 98%Severity: 86%
Audit Metadata
Analyzed At
Sep 8, 2026, 10:32 PM
Package URL
pkg:socket/skills-sh/j4flmao%2Fagent-skills%2Ffirebase%2F@a1f6f18df947e68693646a2cb61e2d89db7d46253d260a093c61245b54fedb2f
Security Audit — socket — firebase