firebase-apk-scanner

Warn

Audited by Socket on Sep 15, 2026

2 alerts found:

Anomalyx2
AnomalyLOW
SKILL.md

SUSPICIOUS. The stated purpose and official Firebase data flows are coherent for a security-audit skill, and there is no evidence of credential harvesting, third-party proxying, or malicious pre-execution. However, the referenced bundled scanner.sh is not provided for review, so core execution behavior is partially unverifiable, and the skill performs active offensive security testing against live targets; that makes it high-risk in operation and not suitable outside explicit authorization.

Confidence: 90%Severity: 68%
AnomalyLOW
scanner.sh

The code is a legitimate-looking Firebase security scanner and contains no clear malware, persistence, exfiltration, or host compromise behavior. It does perform active network reconnaissance and modifies remote Firebase resources by creating accounts and writing test data. It also stores authentication tokens in local reports and insufficiently validates APK-derived URL components. Use only with authorization, isolate and protect generated reports, and improve input validation and cleanup handling.

Confidence: 97%Severity: 58%
Audit Metadata
Analyzed At
Sep 15, 2026, 02:33 AM
Package URL
pkg:socket/skills-sh/trailofbits%2Fskills%2Ffirebase-apk-scanner%2F@2944f123b1f08bc47bbd00d5254286586b97b134c8b88b241512f45809024beb
Security Audit — socket — firebase-apk-scanner