firebase-firestore
Pass
Audited by Gen Agent Trust Hub on Apr 6, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill implements a robust architecture for database operations, emphasizing the use of environment variables for sensitive Firebase credentials and the 'server-only' directive to ensure administrative SDK logic is never exposed to the client.
- [SAFE]: The provided patterns include explicit guidance on input validation and data sanitization (detailed in 'patterns.md'), which are critical for preventing common database vulnerabilities and ensuring data integrity.
- [SAFE]: All external dependencies (e.g., firebase-admin, zod) are well-known, reputable packages used for their intended purposes. There are no instances of remote code execution, obfuscation, or unauthorized data exfiltration.
- [SAFE]: The use of the ServiceError contract and tuple return types promotes explicit error handling, reducing the likelihood of unhandled exceptions or silent failures that could lead to insecure application states.
Audit Metadata