هذا التقرير غير مترجم إلى اللغة المطلوبة. يتم عرض التقرير الإنجليزي الأساسي بدلاً منه.

تقييم أمني مُحدَّث بالإصدار

معرّف التقرير: SA-78A3A38E

6/30/2026, 12:37:22 AM

firebase-app-hosting-basics تقييم أمني v2

تقرير شهادة أمان المهارة

سجل التدقيق
نموذج التدقيق: codex تقرير تاريخي
اسم المهارة
firebase-app-hosting-basics
الإصدار
v2
المشرف
firebase
التغطية
4 الملفات التي تم فحصها · 230 الأسطر التي تم تحليلها
إصدار السياسة
غير متاح

أعلى مستوى خطورة لنتيجة مؤكدة

متوسط

تتطلب 2 اكتشافات أمنية مؤكدة اهتمامًا.

سياق التثبيت

الأدلة التاريخية

قد لا يصف هذا التقرير العنصر القابل للتثبيت حاليًا. افتح صفحة المهارة الحالية للحصول على إرشادات التثبيت.

افتح صفحة Skill الحالية

لا يحظر هذا التقرير البيان أو ملف ZIP ولا يصرح بهما.

Static analysis flagged a critical combination of commands, network references, and secret terms, but review found documentation-only Markdown with no executable code, obfuscation, prompt injection, or data exfiltration. Most static hits are false positives from Markdown backticks, prose, or official Firebase examples. Risk remains medium because the skill guides agents through Firebase CLI commands that can deploy, delete, or change cloud resources and manage secrets.

موضع التقرير

تقرير تاريخي

افتح سجل التدقيق قبل استخدام هذا التقرير للتثبيت.

إقرار التدقيق

غير قابل للتصديق

الربط الثابت المطلوب غير مكتمل.

التحقق البشري

لم يتم التحقق منه

لم يتم تسجيل أي تحقق بشري لهذا التقرير.

التغطية

4 الملفات التي تم فحصها · 230 الأسطر التي تم تحليلها

2 عناصر معروضة للمراجعة

القيود

لا يدّعي هذا التقرير تنفيذًا في وقت التشغيل أو ضمن بيئة معزولة، ولا يثبت عدم وجود آثار جانبية.

سلسلة الأدلة

اتبع الأدلة من ربط المصدر إلى عقد التثبيت. تدعم الأدلة المتاحة التحقق؛ لكنها ليست ضمانًا للسلامة.

  1. المصدر

    الربط غير متاح

  2. العنصر البرمجي

    الهوية غير مكتملة

  3. التدقيق

    مكتمل

  4. عقد التثبيت

    افتح البيان للتحقق

    افتح البيان

القدرات المرصودة

تعني «تمت ملاحظته» أن هذا التقرير سجل أدلة داعمة. ولا يثبت عدم التسجيل أن القدرة غير موجودة.

يحتوي على سكربتات

قد ينفذ تعليمات برمجية مضمنة مع المهارة.

لم يتم تسجيله بواسطة هذا التدقيق

الوصول إلى الشبكة

قد يتصل بخدمات خارجية.

تمت ملاحظته في 2 مواضع أدلة

الوصول إلى نظام الملفات

قد يقرأ أو يكتب ملفات محلية.

لم يتم تسجيله بواسطة هذا التدقيق

متغيرات البيئة

قد يقرأ قيماً من بيئة العملية.

تمت ملاحظته في 2 مواضع أدلة

الأوامر الخارجية

قد يستدعي أوامر أو برامج خارج المهارة.

تمت ملاحظته في 7 مواضع أدلة

نتائج المخاطر

يتم فصل المخاوف الأمنية المؤكدة عن العناصر التي لا تزال بحاجة إلى مراجعة.

مخاوف أمنية مؤكدة (2)

RISK-001 متوسط
Firebase CLI Commands Can Modify Cloud Resources
The skill documents Firebase CLI commands for deployment, backend deletion, rollout creation, backend creation, and secret access. These are legitimate App Hosting workflows, but they can change or delete Firebase resources if run without clear user approval.
The commands are plainly documented and include deploy, delete, create, and rollout operations. They are legitimate Firebase commands, but the operational impact is real.
RISK-002 متوسط
Secret Handling Workflow Requires User Confirmation
The skill includes App Hosting secret commands and examples using API_KEY values. This is expected for Firebase App Hosting, but agents must avoid exposing secret values in logs, commits, prompts, or generated files.
The files clearly describe secret creation and local secret overrides. The guidance is not malicious, but mishandling these workflows could expose credentials.

أدلة الخبراء

هوية موضوع غير قابلة للتغيير، وبيانات تعريف الماسح الضوئي، والمطابقات المستبعدة، والأدلة على مستوى المصدر.

موضوع العنصر البرمجي

التزام Marketplace
غير متاح
تجزئة المحتوى
غير متاح
تجزئة الشجرة
غير متاح
مسار Skill
غير متاح
تجزئة حمولة التدقيق
غير متاح

البيانات الوصفية للتحليل

نموذج التدقيق: codex

حالة التحليل: مكتمل

النطاق محدود بالملفات والأسطر والأساليب والأدلة المسجلة. لا يُدّعى تنفيذ وقت التشغيل أو بيئة الاختبار المعزولة.

تم تجاهل الإيجابيات الكاذبة الثابتة (3)
منخفض
Markdown Backtick Command Alerts Are Mostly False Positives
The static analyzer labeled many Markdown backtick snippets as Ruby or shell backtick execution. The reviewed files contain documentation and fenced examples, not executable Ruby code or dynamic shell evaluation.
The cited locations are Markdown headings, inline code, or fenced examples. No file contains Ruby code, eval behavior, or shell interpolation logic.
منخفض
Weak Cryptography Alerts Lack Supporting Evidence
Static analysis reported weak cryptographic algorithm blockers, but the cited lines are prose or configuration guidance. No evidence found of MD5, SHA1, insecure cipher use, or custom cryptography in the reviewed files.
The cited lines do not contain cryptographic APIs or algorithm names. They describe Firebase App Hosting and local emulator configuration.
منخفض
Network Findings Are Documentation References
The hardcoded URL points to the official Firebase Console billing page, and the configuration line flagged as network access is an environment availability value. No evidence found of outbound HTTP requests or data transmission code.
The only real URL is an official Firebase Console link for plan setup. The other cited line is the word RUNTIME in a YAML example, not a Python HTTP library.

التحقق والتصدير

يربط البيان وملف القفل عناصر التثبيت بتجزئات تشفيرية. هذا الادعاء المتعلق بالسلامة منفصل عن التقييم الأمني.

إقرار التدقيق: not_attestable