firestore-security-rules-auditor
78Audit Firestore Security Rules
Firestore rules often miss update bypasses, ownership checks, and validation gaps. This skill guides Claude, Codex, or Claude Code through a focused security review.
Configure Firestore with Secure Rules
Firestore projects need correct setup, indexes, SDK usage, and security rules. This skill guides database workflows and rule design for safer launches.
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "firebase-firestore" from https://skillstore.io/skills/firebase-firebase-firestore.md and its manifest at https://skillstore.io/api/skills/firebase-firebase-firestore/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.Your Agent should still show its plan and request any confirmation required by the security policy.
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Using "firebase-firestore". I need Firestore for a new app.
Expected outcome:
A setup plan with edition choice, location questions, initial configuration files, emulator steps, and deployment checks.
Using "firebase-firestore". My users collection stores public profiles and private emails.
Expected outcome:
A recommendation to split public and private data, restrict owner-only reads, and validate all write fields.
Using "firebase-firestore". My app filters tasks by owner, status, and due date.
Expected outcome:
An index plan that maps each query shape to required fields, ordering, and deployment steps.
Most static findings are false positives from Markdown examples, Firestore Rules syntax, or defensive security guidance. Five findings are confirmed because SKILL.md instructs agents to run Firebase CLI commands through npx, including metadata reads and database creation. No evidence found of prompt injection, credential exfiltration, or malicious intent.
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
https://skillstore.io/skills/firebase-firebase-firestore/audits/6?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report[](https://skillstore.io/skills/firebase-firebase-firestore?utm_source=security_passport_badge)<a href="https://skillstore.io/skills/firebase-firebase-firestore?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/firebase-firebase-firestore/security.svg" alt="Skillstore security assessment" loading="lazy"></a><iframe src="https://skillstore.io/embed/skills/firebase-firebase-firestore.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>firebase. (2026). firebase-firestore security audit report (audit version 6) [Author version unspecified]. Skillstore. https://skillstore.io/skills/firebase-firebase-firestore/audits/6@techreport{firebase-firebase-firebase-firestore-2026,
author = {firebase},
title = {firebase-firestore security audit report (audit version 6)},
institution = {Skillstore},
year = {2026},
number = {6},
url = {https://skillstore.io/skills/firebase-firebase-firestore/audits/6},
note = {Author version unspecified}
}cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "firebase-firestore security audit report (audit version 6)"
version: "unspecified"
type: report
authors:
- name: "firebase"
date-released: "2026-07-09"
url: "https://skillstore.io/skills/firebase-firebase-firestore/audits/6"
identifiers:
- type: other
value: "skillstore:firebase-firebase-firestore:audit:6"
description: "Skillstore immutable audit report identifier"
Create the database plan, configuration files, emulator setup, and initial locked-down rules.
Review collections, ownership rules, validation checks, and attack scenarios before release.
Map application queries to required single-field, composite, sparse, or unique indexes.
Help me choose a Firestore database setup for my app. Ask what project, region, and client platforms I use.
Guide me through adding Firestore to my app. Include the right SDK path, initialization steps, and safe query patterns.
Analyze my Firestore collections and write prototype Security Rules. Include validation, ownership checks, and assumptions to review.
Review my Firestore rules and query patterns. Identify bypass risks, missing validations, and required indexes before deployment.
Author
firebaseLicense
MIT
Skillstore revision
r1
Version notice
The author did not declare a version.
Ref
0519034dad657fb1f7706e0550e962beeda73fdf
Maintenance freshness
7/18/2026
Usage
1 downloads ยท 8 views
File structure
๐ references/
๐ enterprise/
๐ android_sdk_usage.md
๐ data_model.md
๐ flutter_setup.md
๐ indexes.md
๐ ios_setup.md
๐ provisioning.md
๐ python_sdk_usage.md
๐ security_rules.md
๐ web_sdk_usage.md
๐ standard/
๐ android_sdk_usage.md
๐ flutter_setup.md
๐ indexes.md
๐ ios_setup.md
๐ provisioning.md
๐ security_rules.md
๐ web_sdk_usage.md
๐ SKILL.md
Audit Firestore Security Rules
Firestore rules often miss update bypasses, ownership checks, and validation gaps. This skill guides Claude, Codex, or Claude Code through a focused security review.
Integrate Firebase AI Logic in Apps
Adding Gemini features to Firebase apps requires platform-specific setup and production safeguards. This skill provides focused Firebase AI Logic guidance for web, mobile, and Flutter projects.
Audit Firebase Security Rules
Firestore rules can accidentally allow data leaks, role escalation, or unsafe updates. This skill guides Claude, Codex, and Claude Code through a focused review of access control and validation gaps.
Build Firestore Standard Apps Safely
Firestore setup can fail when rules, indexes, and SDK usage are planned separately. This skill helps Claude, Codex, and Claude Code create secure project files, validate access patterns, and guide Web SDK integration.
Integrate Firebase AI Logic
Developers often need Firebase AI features without maintaining a separate backend. This skill guides setup, Gemini model usage, multimodal prompts, structured output, and production security for web apps.
Build Genkit JS Apps
Genkit changes quickly, and outdated examples cause broken TypeScript flows. This skill guides setup, documentation lookup, examples, and troubleshooting for current Genkit JavaScript work.
Automate DevOps Pipelines and Deployments
by alirezarezvani
DevOps work often requires repeatable pipeline, infrastructure, and deployment patterns. This skill provides scripts and reference guides for CI/CD, IaC, deployment, and operations review.
Coordinate Cloud DevOps Workflows
by sickn33
Cloud delivery work often spans many tools and phases. This skill organizes infrastructure, CI/CD, Kubernetes, monitoring, security, costs, and recovery work into clear prompts.
Build Terraform Infrastructure Workflows
by sickn33
Terraform work often spans setup, modules, state, environments, pipelines, and security controls. This skill organizes those steps into a clear infrastructure workflow.
Manage CloudBase From the CLI
by tencentcloudbase
CloudBase teams need repeatable command-line workflows for deployments and resource changes. This skill guides Claude, Codex, and Claude Code through tcb CLI tasks.
Build Reliable Backend APIs
by alirezarezvani
Backend projects often need consistent planning across APIs, databases, security, and deployment. This skill gives Claude, Codex, and Claude Code structured backend guidance with simple helper scripts and references.
Optimize Supabase Postgres Performance
by supabase
Slow queries and schema drift can make Postgres apps hard to scale. This skill gives AI agents Supabase-backed rules for indexes, RLS, pooling, and diagnostics.