{"data":{"skill":{"slug":"firebase-firebase-firestore","name":"firebase-firestore","icon":"📦","repo":"https://github.com/firebase/agent-skills/tree/main/skills/firebase-firestore/","status":"approved","author":"firebase","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"d68ea881-56dd-4f35-a499-051532d9e22b","skill_id":"98da0f51-0f79-4c4b-b180-42559a9d7cd8","version":1,"content_hash":"a8cb1d329d11f5b982c8c3ee16e979b6","risk_level":"low","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":null,"manual_install_policy":null,"summary":"Static analysis flagged 737 potential issues with a computed risk score of 100/100, but all findings are false positives from documentation code examples. The 615 external_commands detections are markdown code fences (```bash) and inline backticks in reference docs showing Firebase CLI commands like 'npx firebase-tools'. The 9 network detections are legitimate Firebase documentation URLs and placeholder project endpoints. Weak crypto, system reconnaissance, and certificate/key file detections all appear in security rules teaching examples and setup instructions. One critical heuristic finding combining code execution + network + credential patterns is expected in Firebase documentation that teaches CLI usage, API endpoints, and service account setup. The skill's inherent behaviors (instructing users to run Firebase CLI commands, referencing Firebase URLs) are core to its purpose as a Firestore setup and management guide. No malicious intent, no prompt injection, no data exfiltration patterns found.","remediation":[],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"SKILL.md","line_end":60,"line_start":9},{"file":"references/enterprise/provisioning.md","line_end":112,"line_start":5},{"file":"references/enterprise/security_rules.md","line_end":531,"line_start":25},{"file":"references/standard/provisioning.md","line_end":97,"line_start":5},{"file":"references/standard/security_rules.md","line_end":531,"line_start":25},{"file":"references/enterprise/android_sdk_usage.md","line_end":137,"line_start":9},{"file":"references/standard/ios_setup.md","line_end":125,"line_start":5}]},{"factor":"network","evidence":[{"file":"references/standard/android_sdk_usage.md","line_end":21,"line_start":21},{"file":"references/enterprise/provisioning.md","line_end":117,"line_start":117},{"file":"references/enterprise/security_rules.md","line_end":141,"line_start":141},{"file":"references/standard/security_rules.md","line_end":141,"line_start":141}]}],"critical_findings":[],"high_findings":[],"medium_findings":[],"low_findings":[{"title":"Shell command execution instructions","locations":[{"file":"SKILL.md","line_end":20,"line_start":19},{"file":"SKILL.md","line_end":42,"line_start":38},{"file":"references/enterprise/provisioning.md","line_end":30,"line_start":24}],"description":"The skill instructs the AI to run shell commands via npx firebase-tools for database provisioning, listing, and creation. These commands (firestore:databases:list, firestore:databases:create, firestore:locations) are legitimate Firebase CLI operations inherent to the skill's purpose. No user input is interpolated into command arguments. Risk is low and expected for a Firebase management skill."},{"title":"Reference URLs in documentation","locations":[{"file":"references/standard/android_sdk_usage.md","line_end":21,"line_start":21},{"file":"references/enterprise/security_rules.md","line_end":141,"line_start":141}],"description":"Documentation contains hardcoded URLs to Firebase services (firebase.google.com, firebaseio.com) and placeholder project URLs. These are legitimate references for users to look up Firebase BoM versions, API documentation, and project endpoints. No data is sent to these URLs by the skill itself."}],"dangerous_patterns":[{"title":"Documentation code blocks misidentified as shell execution","locations":[{"file":"SKILL.md","line_end":60,"line_start":9},{"file":"references/enterprise/security_rules.md","line_end":531,"line_start":25},{"file":"references/standard/security_rules.md","line_end":531,"line_start":25}],"description":"615 instances of markdown code fences (```bash, ```kotlin, ```swift, etc.) and inline backticks in reference markdown files were misidentified by the static scanner as Ruby/shell backtick execution. These are standard markdown syntax for displaying code examples. All instances are benign documentation content showing Firebase CLI commands, SDK code snippets, and configuration examples."},{"title":"Security documentation misidentified as weak cryptography","locations":[{"file":"references/enterprise/security_rules.md","line_end":566,"line_start":12},{"file":"references/standard/security_rules.md","line_end":566,"line_start":12}],"description":"Multiple instances of hash algorithm references (SHA1, SHA256) and cryptographic terms in security rules documentation were flagged as weak cryptographic algorithms. These appear in Firestore security rules teaching examples and documentation about hashing patterns, not in actual cryptographic implementations."}],"files_scanned":17,"total_lines":3190,"audit_model":"claude","audited_at":"2026-05-25T09:32:53.264+00:00","created_at":"2026-05-25T11:16:07.928498+00:00","static_findings":[],"finding_verdicts":[],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"canonical install advisories are incomplete"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"safe","confirmedFindingCount":0,"capabilityReviewCount":1,"needsReviewCount":0,"falsePositiveCount":1,"agentAutoInstallPolicy":null,"manualInstallPolicy":null,"artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}