firebase-launchpad
Warn
Audited by Socket on Aug 10, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the stated purpose, credentials, and official service endpoints are broadly coherent for Firebase/Expo provisioning, so this is not clearly malicious. However, it relies on transitive skill installation and unseen pnpm template scripts while handling high-privilege Google and Expo credentials, which makes the overall security risk medium even though the data flows appear purpose-aligned.
Confidence: 81%Severity: 56%
Audit Metadata