firebase-security-expert

Pass

Audited by Gen Agent Trust Hub on Jul 1, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides comprehensive and legitimate security auditing guidelines for the Firebase ecosystem. It explicitly warns against insecure practices such as committing service account keys to repositories or leaving database rules open to the public.
  • [PROMPT_INJECTION]: The skill is designed to process and audit untrusted data, specifically user-provided Firebase security rules (Firestore/RTDB/Storage) and Cloud Function code. This creates a surface for indirect prompt injection where instructions embedded within the code being audited could attempt to influence the agent's behavior. The instructions lack explicit boundary markers or sanitization steps to mitigate this specific vector, though this is a common characteristic of auditing tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 1, 2026, 02:51 PM
Security Audit — agent-trust-hub — firebase-security-expert