firebase-basics

Pass

Audited by Gen Agent Trust Hub on Apr 5, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill frequently executes the official Firebase CLI (firebase-tools) via npx to perform administrative tasks such as authentication, project creation, and service deployment. This is standard practice to ensure the latest tools are used.
  • [EXTERNAL_DOWNLOADS]: Instructions guide the agent to fetch and update additional skills and plugins from the official firebase and vercel-labs GitHub organizations. These sources are established and trusted within the developer community.
  • [COMMAND_EXECUTION]: The setup process involves modifying local configuration files (e.g., mcp_config.json, .bashrc, .zshrc) to register Model Context Protocol (MCP) servers and manage Node.js versions. These actions are transparently documented as prerequisites for the skill's functionality.
  • [DATA_EXFILTRATION]: While the skill involves authentication (firebase login), it leverages the official OAuth flow provided by the Firebase CLI. No evidence of unauthorized credential harvesting or sensitive data transmission to third-party domains was detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 5, 2026, 06:41 PM
Security Audit — agent-trust-hub — firebase-basics