firestore-security-rules-auditor
78Audit Firestore Security Rules
Firestore rules often miss update bypasses, ownership checks, and validation gaps. This skill guides Claude, Codex, or Claude Code through a focused security review.
Set Up Firebase Projects with AI Agents
Firebase setup often requires CLI, authentication, and project context checks. This skill guides Claude, Codex, and Claude Code through Firebase setup workflows.
Stop for confirmation before installing.
Review the plan and obtain explicit user consent before changing files.
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "firebase-basics" from https://skillstore.io/skills/firebase-firebase-basics.md and its manifest at https://skillstore.io/api/skills/firebase-firebase-basics/manifest. Verify the artifact. Stop and obtain explicit user consent before installing or changing files.Your Agent should still show its plan and request any confirmation required by the security policy.
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Using "firebase-basics". Check whether my machine is ready for Firebase development.
Expected outcome:
Using "firebase-basics". Help me connect Cursor to Firebase MCP.
Expected outcome:
Using "firebase-basics". Add Firebase to my web app.
Expected outcome:
Most static filesystem, network, environment, and reconnaissance alerts are false positives from setup documentation, placeholders, and Markdown formatting. Several Firebase CLI instructions are confirmed as medium-risk because they run npx-based tooling, authenticate users, or alter project context. The main semantic concern is forceful agent-control wording that may override normal user intent.
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
https://skillstore.io/skills/firebase-firebase-basics/audits/4?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report[](https://skillstore.io/skills/firebase-firebase-basics?utm_source=security_passport_badge)<a href="https://skillstore.io/skills/firebase-firebase-basics?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/firebase-firebase-basics/security.svg" alt="Skillstore security assessment" loading="lazy"></a><iframe src="https://skillstore.io/embed/skills/firebase-firebase-basics.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>firebase. (2026). firebase-basics security audit report (audit version 4) [Author version unspecified]. Skillstore. https://skillstore.io/skills/firebase-firebase-basics/audits/4@techreport{firebase-firebase-firebase-basics-2026,
author = {firebase},
title = {firebase-basics security audit report (audit version 4)},
institution = {Skillstore},
year = {2026},
number = {4},
url = {https://skillstore.io/skills/firebase-firebase-basics/audits/4},
note = {Author version unspecified}
}cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "firebase-basics security audit report (audit version 4)"
version: "unspecified"
type: report
authors:
- name: "firebase"
date-released: "2026-07-06"
url: "https://skillstore.io/skills/firebase-firebase-basics/audits/4"
identifiers:
- type: other
value: "skillstore:firebase-firebase-basics:audit:4"
description: "Skillstore immutable audit report identifier"
Verify Node.js, install Firebase CLI access, sign in, and select the correct active project before development begins.
Add or verify Firebase MCP configuration for tools such as Claude Code, Cursor, Gemini CLI, GitHub Copilot, and Antigravity.
Use Firebase CLI guidance to create projects, initialize services, and add Firebase web SDK setup to an application.
Use the firebase-basics skill to check whether my local environment is ready for Firebase development. Ask before running commands.
Use the firebase-basics workflow to verify my active Firebase project and help me set the correct project alias.
Use firebase-basics to review my agent environment and propose Firebase MCP setup steps. Show any configuration changes before applying them.
Use firebase-basics to create a Firebase setup plan for this web app, including project creation, service initialization, SDK setup, and verification.
Author
firebaseLicense
MIT
Skillstore revision
r1
Version notice
The author did not declare a version.
Ref
a06681402992ceae98ba04d54cfd4ab004862696
Maintenance freshness
7/18/2026
Usage
2 downloads ยท 90 views
File structure
๐ references/
๐ firebase-project-create.md
๐ local-env-setup.md
๐ refresh-claude.md
๐ setup-antigravity.md
๐ setup-claude_code.md
๐ setup-cursor.md
๐ setup-gemini_cli.md
๐ web_setup.md
๐ SKILL.md
Audit Firestore Security Rules
Firestore rules often miss update bypasses, ownership checks, and validation gaps. This skill guides Claude, Codex, or Claude Code through a focused security review.
Integrate Firebase AI Logic in Apps
Adding Gemini features to Firebase apps requires platform-specific setup and production safeguards. This skill provides focused Firebase AI Logic guidance for web, mobile, and Flutter projects.
Audit Firebase Security Rules
Firestore rules can accidentally allow data leaks, role escalation, or unsafe updates. This skill guides Claude, Codex, and Claude Code through a focused review of access control and validation gaps.
Build Firestore Standard Apps Safely
Firestore setup can fail when rules, indexes, and SDK usage are planned separately. This skill helps Claude, Codex, and Claude Code create secure project files, validate access patterns, and guide Web SDK integration.
Integrate Firebase AI Logic
Developers often need Firebase AI features without maintaining a separate backend. This skill guides setup, Gemini model usage, multimodal prompts, structured output, and production security for web apps.
Build Genkit JS Apps
Genkit changes quickly, and outdated examples cause broken TypeScript flows. This skill guides setup, documentation lookup, examples, and troubleshooting for current Genkit JavaScript work.
Fix Windows AI Agent Encoding
by gkd2323c
Windows POSIX shells can garble Chinese output from Python, PowerShell, and cmd.exe. This skill gives targeted UTF-8 and GBK fixes for Claude, Codex, and related agents.
Optimize LLM Prompts and Agent Instructions
by 89jobrien
Weak prompts create inconsistent model outputs and slow AI feature development. This skill helps structure prompts, examples, constraints, and output formats for Claude, Codex, and Claude Code.
Organize Obsidian Notes with AI
by ZhanlinCui
Obsidian vaults can become hard to review and update consistently. This skill helps Claude and Codex create daily notes, capture ideas, and summarize recent work.
Design Reliable Tools for AI Agents
by Asmayaseen
Ambiguous tools cause incorrect calls, wasted context, and poor recovery from errors. This skill provides practical patterns for clear descriptions, schemas, responses, and testing.
Build WorkPaper Spreadsheet Automation
by proompteng
Agents often need spreadsheet logic without controlling Excel. This skill guides MCP and TypeScript workflows for WorkPaper formulas, file-backed edits, and local XLSX formula reports.
Diagnose Context Degradation in AI Agents
by ChakshuGautam
Long conversations and large prompts can make AI agents lose important information or follow conflicting context. This skill helps Claude, Codex, and Claude Code identify degradation patterns and choose mitigation strategies.