firebase-ops

Pass

Audited by Gen Agent Trust Hub on Jun 21, 2026

Risk Level: SAFECOMMAND_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes the firebase CLI tool to perform various project management tasks such as uploading symbols and managing Remote Config.
  • [COMMAND_EXECUTION]: The scripts/fcm-send.sh script uses curl, openssl, and python3 to construct and send authenticated HTTP requests to Google APIs.
  • [DATA_EXFILTRATION]: The skill accesses a sensitive credential file located at ~/.nutrisport/firebase/service-account.json. This access is necessary for the intended function of the skill (authenticating with Firebase) and is documented with instructions for secure local storage and .gitignore protection.
  • [EXTERNAL_DOWNLOADS]: The script interacts with well-known Google services at oauth2.googleapis.com and fcm.googleapis.com to obtain access tokens and send messages.
  • [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection as it processes user-provided or agent-retrieved data (notification titles, bodies, and data payloads) and sends it to an external API.
  • Ingestion points: CLI arguments passed to scripts/fcm-send.sh (e.g., --title, --body, --data).
  • Boundary markers: None present in the prompt interpolation.
  • Capability inventory: Network POST via curl in scripts/fcm-send.sh.
  • Sanitization: The script uses Python's json.dumps to correctly escape data before sending the JSON payload, which prevents schema confusion but does not filter for malicious instruction content.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 21, 2026, 06:05 PM