firestore-security-rules-auditor
78Audit Firestore Security Rules
Firestore rules often miss update bypasses, ownership checks, and validation gaps. This skill guides Claude, Codex, or Claude Code through a focused security review.
Configure Xcode Swift Packages Safely
Adding Swift Packages to Xcode projects can be error-prone and easy to break. This skill uses a bundled Swift tool to add packages, link products, and handle Firebase plist setup.
Copy this request to your Agent. It includes the canonical Skill page and manifest.
Review the Skillstore skill "xcode-project-setup" from https://skillstore.io/skills/firebase-xcode-project-setup.md and its manifest at https://skillstore.io/api/skills/firebase-xcode-project-setup/manifest. Verify the artifact. You may proceed after verification, subject to the environment's own policy.Your Agent should still show its plan and request any confirmation required by the security policy.
Use these links when an AI agent, crawler, or script needs clean context instead of reading the full page.
Using "xcode-project-setup". Add Alamofire to an existing app project.
Expected outcome:
Using "xcode-project-setup". Add FirebaseAuth with the service plist.
Expected outcome:
Using "xcode-project-setup". Configure FirebaseCrashlytics for a target.
Expected outcome:
The Swift helper performs legitimate Xcode project automation, but it introduces low supply-chain exposure through remote SwiftPM dependencies and package URLs. The main confirmed execution risk is the intentional Crashlytics shell build phase, while most SKILL.md backtick findings are Markdown false positives. No prompt injection attempt or hidden data exfiltration intent was found.
These are real local capabilities that may be expected for this skill, so they require review but are not counted as confirmed malicious behavior.
Share the versioned assessment report, neutral badge, embed card, and citations. Skillstore reports evidence without deciding whether this Skill is safe.
https://skillstore.io/skills/firebase-xcode-project-setup/audits/4?utm_source=security_passport&utm_medium=share&utm_campaign=versioned_report[](https://skillstore.io/skills/firebase-xcode-project-setup?utm_source=security_passport_badge)<a href="https://skillstore.io/skills/firebase-xcode-project-setup?utm_source=security_passport_badge"><img src="https://skillstore.io/badges/skills/firebase-xcode-project-setup/security.svg" alt="Skillstore security assessment" loading="lazy"></a><iframe src="https://skillstore.io/embed/skills/firebase-xcode-project-setup.html" title="Skillstore Security Assessment" sandbox="allow-popups allow-popups-to-escape-sandbox" loading="lazy" referrerpolicy="no-referrer" width="420" height="180"></iframe>firebase. (2026). xcode-project-setup security audit report (audit version 4) [Author version unspecified]. Skillstore. https://skillstore.io/skills/firebase-xcode-project-setup/audits/4@techreport{firebase-firebase-xcode-project-setup-2026,
author = {firebase},
title = {xcode-project-setup security audit report (audit version 4)},
institution = {Skillstore},
year = {2026},
number = {4},
url = {https://skillstore.io/skills/firebase-xcode-project-setup/audits/4},
note = {Author version unspecified}
}cff-version: 1.2.0
message: "If you use this Skill, cite its author and this versioned security audit report."
title: "xcode-project-setup security audit report (audit version 4)"
version: "unspecified"
type: report
authors:
- name: "firebase"
date-released: "2026-07-05"
url: "https://skillstore.io/skills/firebase-xcode-project-setup/audits/4"
identifiers:
- type: other
value: "skillstore:firebase-xcode-project-setup:audit:4"
description: "Skillstore immutable audit report identifier"
Install a Swift Package dependency and link its product into an existing app target.
Add Firebase products, include the service plist, and apply required linker settings.
Use the same Swift helper to avoid fragile manual edits to Xcode project files.
Add Alamofire to my existing Xcode project and link it to the app target. Check the project first and explain any required confirmation.
Configure FirebaseCore and FirebaseAuth in my Xcode project. Use the existing GoogleService-Info plist and verify the required linker settings.
Inspect my Xcode project setup for the requested Swift Package. Link any missing products without duplicating existing dependencies.
Add FirebaseCrashlytics to my app target, configure dSYM settings, and tell me before adding any build script phase.
Author
firebaseLicense
MIT
Skillstore revision
r1
Version notice
The author did not declare a version.
Ref
30c73eac2afe762f6aa9c4553158769369d47351
Maintenance freshness
7/18/2026
Usage
1 downloads ยท 0 views
File structure
๐ scripts/
๐ xcode_spm_setup/
๐ Sources/
๐ main.swift
๐ Package.resolved
๐ Package.swift
๐ SKILL.md
Audit Firestore Security Rules
Firestore rules often miss update bypasses, ownership checks, and validation gaps. This skill guides Claude, Codex, or Claude Code through a focused security review.
Integrate Firebase AI Logic in Apps
Adding Gemini features to Firebase apps requires platform-specific setup and production safeguards. This skill provides focused Firebase AI Logic guidance for web, mobile, and Flutter projects.
Audit Firebase Security Rules
Firestore rules can accidentally allow data leaks, role escalation, or unsafe updates. This skill guides Claude, Codex, and Claude Code through a focused review of access control and validation gaps.
Build Firestore Standard Apps Safely
Firestore setup can fail when rules, indexes, and SDK usage are planned separately. This skill helps Claude, Codex, and Claude Code create secure project files, validate access patterns, and guide Web SDK integration.
Integrate Firebase AI Logic
Developers often need Firebase AI features without maintaining a separate backend. This skill guides setup, Gemini model usage, multimodal prompts, structured output, and production security for web apps.
Build Genkit JS Apps
Genkit changes quickly, and outdated examples cause broken TypeScript flows. This skill guides setup, documentation lookup, examples, and troubleshooting for current Genkit JavaScript work.
Build Native iOS Apps With Swift
by sickn33
Native iOS development requires platform knowledge across UI, data, security, testing, and App Store release work. This skill gives Claude, Codex, and Claude Code focused guidance for Swift-first iOS implementation.
Debug iOS Apps on Simulator
by Dimillian
iOS simulator debugging often requires many separate build, launch, UI, and log steps. This skill gives Claude a clear XcodeBuildMCP workflow for inspecting app behavior in one guided session.
Build Better iOS Apps
by MiniMax-AI
iOS teams need consistent guidance for layouts, navigation, accessibility, and Swift code quality. This skill provides practical UIKit, SwiftUI, and Apple platform patterns for design and review.
Improve SwiftUI Code with Expert Guidance
by avdlee
SwiftUI projects can accumulate state, layout, accessibility, and performance problems. This skill provides focused review guidance and optional Instruments trace analysis to identify practical improvements.
Build iOS Apps with xtool
by 2389-research
SwiftPM iOS projects can be hard to configure without Xcode. This skill gives xtool project setup, extension, resource, entitlement, and troubleshooting guidance.
Build Modern Mobile Applications
by sickn33
Mobile projects require careful choices across platforms, architecture, performance, testing, security, and distribution. This skill provides focused guidance for planning and implementing production mobile applications.