output-firebase-publisher

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests external static directories provided by the user to publish them. This creates a surface for indirect prompt injection where malicious instructions could be embedded in the files. This is mitigated by the skill's strict validation rules that reject symlinks, source maps, remote scripts, and undeclared network dependencies.
  • [EXTERNAL_DOWNLOADS]: The skill uses curl to fetch deployed assets from the public Firebase Hosting URL to verify byte-equivalence and integrity against local digests. It also includes a mechanism for version checking a related skill, which is a standard maintenance operation.
  • [SAFE]: The skill references official Google Firebase documentation for platform constraints and configuration, which are well-known and trusted service URLs.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 09:16 PM
Security Audit — agent-trust-hub — output-firebase-publisher