firebase-security-rules-auditor

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill analyzes Firestore and Cloud Storage security rules and application code, which serves as an ingestion point for untrusted data. \n- Ingestion points: firestore.rules, storage.rules, firebase.json, and source files in src, app, and functions. \n- Boundary markers: None explicitly present in the instructions to separate rules logic from auditing prompts. \n- Capability inventory: Utilizes rg for file searching and firebase emulators for testing. \n- Sanitization: No specific sanitization of the audited files against prompt injection is performed.\n- [COMMAND_EXECUTION]: Employs rg (ripgrep) to inspect project files and the firebase CLI to execute security tests within the Firebase emulator environment.\n- [EXTERNAL_DOWNLOADS]: Fetches configuration and security guidelines from the official Firebase agent-skills repository on GitHub.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 06:57 AM
Security Audit — agent-trust-hub — firebase-security-rules-auditor