firebase-ai-logic
Pass
Audited by Gen Agent Trust Hub on Jun 18, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The instructions guide users to install global command-line tools (firebase-tools) and execute project initialization commands such as firebase login and firebase init.- [EXTERNAL_DOWNLOADS]: The skill specifies the installation of packages from the official npm registry, including firebase, firebase-tools, and @anthropic-ai/sdk. These originate from well-known and trusted technology organizations.- [DATA_EXFILTRATION]: The analyzeImage function involves fetching data from external URLs provided at runtime. This network operation is necessary for the skill's multimodal functionality but represents an ingestion point for external content.- [PROMPT_INJECTION]: The skill demonstrates processing user-provided text prompts and external image data through AI models, creating an indirect prompt injection surface.
- Ingestion points: User-provided prompt parameters in generateContent and analyzeImage, and remote images fetched via imageUrl in SKILL.md.
- Boundary markers: None provided in the code snippets to delimit untrusted content.
- Capability inventory: No high-risk capabilities like arbitrary shell execution or local file system writes are exposed within the skill's own code.
- Sanitization: No explicit input validation or escaping is implemented in the provided examples.
Audit Metadata