firebase-apk-scanner

Warn

Audited by Socket on Sep 17, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

SUSPICIOUS. The stated purpose and official Firebase data flows are coherent for a security-audit skill, and there is no evidence of credential harvesting, third-party proxying, or malicious pre-execution. However, the referenced bundled scanner.sh is not provided for review, so core execution behavior is partially unverifiable, and the skill performs active offensive security testing against live targets; that makes it high-risk in operation and not suitable outside explicit authorization.

Confidence: 90%Severity: 68%
AnomalyLOW
scanner.sh

The code is a legitimate-looking Firebase security scanner and contains no clear malware, persistence, exfiltration, or host compromise behavior. It does perform active network reconnaissance and modifies remote Firebase resources by creating accounts and writing test data. It also stores authentication tokens in local reports and insufficiently validates APK-derived URL components. Use only with authorization, isolate and protect generated reports, and improve input validation and cleanup handling.

Confidence: 97%Severity: 58%
Audit Metadata
Analyzed At
Sep 17, 2026, 04:53 AM
Package URL
pkg:socket/skills-sh/trailofbits%2Fskills%2Ffirebase-apk-scanner%2F@c31481bceeef42dbae0cf53b4df9443351d6b41b6f1a626cbdf37e8577a1150b
Security Audit — socket — firebase-apk-scanner