hunt-firebase
Warn
Audited by Socket on Jul 31, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS/HIGH-RISK. The skill is internally consistent with a red-team exploitation purpose, but that purpose is offensive: it teaches an AI agent to enumerate targets, use leaked keys/tokens, dump data, and test write/delete access on live Firebase and GCP resources. No major third-party supply-chain concerns are present, but the capability set, credential use, and disabled TLS checks make the skill dangerous.
Confidence: 97%Severity: 95%
Audit Metadata