{"data":{"skill":{"slug":"firebase-firebase-auth-basics","name":"firebase-auth-basics","icon":"📦","repo":"https://github.com/firebase/agent-skills/tree/main/skills/firebase-auth-basics/","status":"approved","author":"firebase","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"60931805-6536-4233-a4cf-8f4bd0902699","skill_id":"92adaa07-d122-4532-a75c-c2440a852fff","version":2,"content_hash":"fc37b335d43122d0dfe5074d990e8a28","risk_level":"medium","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":null,"manual_install_policy":null,"summary":"The static analyzer reported many command execution, weak cryptography, and network patterns, but review found these are markdown examples, Firebase CLI references, localhost emulator setup, or documentation links. No prompt injection, malicious code execution, credential exfiltration, or hidden behavior was found. The main confirmed concern is an email-link sample that stores an email address in browser localStorage.","remediation":[],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":4,"line_start":4},{"file":"SKILL.md","line_end":9,"line_start":9}]},{"factor":"network","evidence":[{"file":"references/client_sdk_web.md","line_end":25,"line_start":25},{"file":"references/client_sdk_web.md","line_end":217,"line_start":217},{"file":"references/client_sdk_web.md","line_end":266,"line_start":266},{"file":"SKILL.md","line_end":73,"line_start":73}]}],"critical_findings":[],"high_findings":[],"medium_findings":[{"title":"Email Address Stored In Browser LocalStorage","locations":[{"file":"references/client_sdk_web.md","line_end":224,"line_start":224},{"file":"references/client_sdk_web.md","line_end":239,"line_start":239},{"file":"references/client_sdk_web.md","line_end":246,"line_start":246}],"confidence":0.9,"description":"The email-link authentication example stores a user's email address in window.localStorage, reads it later, and removes it after successful sign-in. This is a privacy-sensitive browser storage pattern because localStorage is persistent and accessible to scripts running in the origin.","confidence_reasoning":"The storage operations are explicit and tied to an email address used during sign-in. The pattern is common in Firebase examples, but it still creates a browser privacy risk if copied without safeguards."}],"low_findings":[{"title":"Static Command Execution Findings Are Documentation False Positives","locations":[{"file":"SKILL.md","line_end":4,"line_start":4},{"file":"SKILL.md","line_end":9,"line_start":9},{"file":"references/client_sdk_web.md","line_end":13,"line_start":7},{"file":"references/security_rules.md","line_end":13,"line_start":11}],"confidence":0.96,"description":"The command execution findings point to markdown code fences, inline Firebase CLI examples, imports, and Firebase rules syntax. I found no skill script, shell execution logic, Ruby backtick execution, or user-controlled command execution path.","confidence_reasoning":"The cited locations are markdown documentation and code samples, not executable marketplace code. The only actual external command guidance is a Firebase CLI command that users may choose to run."},{"title":"Weak Cryptography Findings Are Authentication Terminology False Positives","locations":[{"file":"SKILL.md","line_end":14,"line_start":14},{"file":"references/client_sdk_web.md","line_end":221,"line_start":215}],"confidence":0.93,"description":"The weak cryptography findings align with authentication terms, token handling, and email-link action settings, not cryptographic algorithm choices. No MD5, SHA-1, custom crypto implementation, or insecure cipher usage was found in the reviewed files.","confidence_reasoning":"The reviewed lines describe Firebase Authentication APIs and an action-code settings object. There is no evidence of cryptographic primitive selection or implementation."},{"title":"Network Findings Are Expected Firebase Documentation Patterns","locations":[{"file":"references/client_sdk_web.md","line_end":25,"line_start":25},{"file":"references/client_sdk_web.md","line_end":217,"line_start":217},{"file":"references/client_sdk_web.md","line_end":266,"line_start":266},{"file":"SKILL.md","line_end":73,"line_start":73}],"confidence":0.88,"description":"The network locations reference a localhost Auth emulator, an example return URL, Firebase API documentation, and Firebase Console. These URLs support normal Firebase setup and do not send secrets to an unknown endpoint.","confidence_reasoning":"The URLs are either local development endpoints, placeholder examples, or Firebase-owned documentation and console pages. I found no hidden network call or exfiltration behavior."}],"dangerous_patterns":[{"title":"Persistent Browser Storage For Sign-In Email","locations":[{"file":"references/client_sdk_web.md","line_end":246,"line_start":224}],"confidence":0.89,"description":"The email-link workflow persists an email address in localStorage before sign-in completes. Users should prefer short-lived storage, clear the value on failure paths, and consider XSS exposure when copying the example.","confidence_reasoning":"The pattern is directly shown in the code sample. It is not malicious, but persistent browser storage is a recognized risk for personal data."}],"files_scanned":3,"total_lines":414,"audit_model":"codex","audited_at":"2026-06-30T00:39:57.193+00:00","created_at":"2026-06-30T01:34:36.279614+00:00","static_findings":[],"finding_verdicts":[],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"canonical install advisories are incomplete"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"medium","confirmedFindingCount":1,"capabilityReviewCount":1,"needsReviewCount":0,"falsePositiveCount":2,"agentAutoInstallPolicy":null,"manualInstallPolicy":null,"artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}