firebase-basics

Warn

Audited by Socket on Apr 22, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The Firebase purpose aligns with the Firebase CLI commands, and data flows appear to go to official Firebase/Google tooling rather than an interceptor. The main concern is the mandatory transitive installation of `firebase/agent-skills` plus unpinned `npx ...@latest` execution, which expands trust beyond this skill and increases supply-chain risk. No clear credential theft or malicious exfiltration is present.

Confidence: 92%Severity: 58%
Audit Metadata
Analyzed At
Apr 22, 2026, 01:09 PM
Package URL
pkg:socket/skills-sh/google%2Fskills%2Ffirebase-basics%2F@6bf63661cb4f0b5c77e070a2a8e0adf24f85631d