hunt-firebase

Warn

Audited by Socket on Jul 31, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS/HIGH-RISK. The skill is internally consistent with a red-team exploitation purpose, but that purpose is offensive: it teaches an AI agent to enumerate targets, use leaked keys/tokens, dump data, and test write/delete access on live Firebase and GCP resources. No major third-party supply-chain concerns are present, but the capability set, credential use, and disabled TLS checks make the skill dangerous.

Confidence: 97%Severity: 95%
Audit Metadata
Analyzed At
Jul 31, 2026, 04:51 PM
Package URL
pkg:socket/skills-sh/uphiago%2Frecon-skills%2Fhunt-firebase%2F@bd0763a1bba8065e16ca2888cc83955dd4bff5719b932702062b6a79b426825b
Security Audit — socket — hunt-firebase