.fyi
SkillsMCPPluginsSubagents

Browse by category

DevOps & CI/CD SkillsProductivity & Workflow SkillsOther SkillsProduct & Project Management SkillsDocumentation & Knowledge SkillsCode Review & Refactor SkillsBackend & APIs SkillsAgent Meta & Communication SkillsResearch SkillsSecurity SkillsUX UI & Design SkillsTesting & QA SkillsSee all →

Every Claude Code skill, MCP server, plugin and subagent in one directory. Searchable, comparable, and one command from installed. Live stats from GitHub, npm and PyPI.

We're on Product HuntYour agent's app storeCheck it out →
Agent SkillsMCP ServersPluginsSubagentsCoding Agents
CollectionsOfficial publishersGlossaryFAQBlogSearchSavedFeedback
PrivacyTermsllms.txtSitemap

made with ♥ · © 2026 aaaa.fyi

Independent project · real data from public registries

…/agent-skills/firebase-security-rules-auditor
home/skills/firebase/agent-skills/firebase-security-rules-auditor
firebase avatar

firebase-security-rules-auditor

byfirebase· 35 skills

Installs

80k

Stars

389

Forks

76

Category

Security

View on GitHub

TL;DR

Audits Firebase (Firestore, Cloud Storage) security rules for vulnerabilities, privilege escalation, role bypasses, create vs update inconsistencies, resource exhaustion, type safety, size limits, and hasOnly ownership checks. Use when auditing/reviewing rules, running red-team rule assessments, or scoring against auditor checklists. Don't use for Firebase CLI (login, deploy), Auth, Crashlytics, Remote Config, or database queries.

How to install firebase-security-rules-auditor?

firebase/agent-skills/firebase-security-rules-auditor
$npx -y skills add firebase/agent-skills --skill firebase-security-rules-auditor

Installs into the current project.

›Prefer a prompt? Paste this to your agent

Use this skill

Run `npx skills use "https://github.com/firebase/agent-skills" --skill "firebase/agent-skills/firebase-security-rules-auditor"` and follow the generated skill instructions now. Read its complete output, redirecting it to a temporary file first if necessary. Resolve relative paths from the supporting-files directory it provides.

Use the whole pack

Use the skills in "https://github.com/firebase/agent-skills" that are relevant to the current task. Run `npx skills add "https://github.com/firebase/agent-skills"` and select the relevant skills, then follow their instructions.

Files · 1

View on GitHub
SKILL.md
1# Overview
2 
3This skill acts as an auditor for Firebase Security Rules, evaluating them
4against a rigorous set of criteria to ensure they are secure, robust, and
5correctly implemented.
6 
7# Scoring Criteria
8 
9## Assessment: Security Validator (Red Team Edition)
10 
11You are a Senior Security Auditor and Penetration Tester specializing in
12Firestore. Your goal is to find "the hole in the wall." Do not assume a rule is
13secure because it looks complex; instead, actively try to find a sequence of
14operations to bypass it.
15 
16### Mandatory Audit Checklist:
17 
181. **The Update Bypass:** Compare 'create' and 'update' rules. Can a user create
19 a valid document and then 'update' it into an invalid or malicious state
20 (e.g., changing their role, bypassing size limits, or corrupting data types)?
211. **Authority Source:** Does the security rely on user-provided data
22 (request.resource.data) for sensitive fields like 'role', 'isAdmin', or
23 'ownerId'? Carefully consider the source for that authority.
241. **Business Logic vs. Rules:** Does the rule set actually support the app's
25 purpose? (e.g., In a collaboration app, can collaborators actually read the
26 data? If not, the rules are "broken" or will force insecure workarounds).
271. **Storage Abuse:** Are there string length or array size limits? If not,
28 label it as a "Resource Exhaustion/DoS" risk.
291. **Type Safety:** Are fields checked with 'is string', 'is int', or 'is
30 timestamp'?
311. **Field-Level vs. Identity-Level Security:** Be careful with rules that use
32 \`hasOnly()\` or \`diff()\`. While these restrict *which* fields can be
33 updated, they do NOT restrict *who* can update them unless an ownership check
34 (e.g., \`resource.data.uid == request.auth.uid\`) is also present. If a rule
35 allows any authenticated user to update fields on another user's document
36 without a corresponding ownership check, it is a data integrity
37 vulnerability.
38 
39### Admin Bootstrapping & Privileges:
40 
41The admin bootstrapping process is limited in this app. If the rules use a
42single hardcoded admin email (e.g., checking request.auth.token.email ==
43'admin@example.com'), this should NOT count against the score as long as:
44 
45- email_verified is also checked (request.auth.token.email_verified == true).
46- It is implemented in a way that does not allow additional admins to add
47 themselves or leave an escalation risk open.
48 
49### Scoring Criteria (1-5):
50 
51- **1 (Critical):** Unauthorized data access (leaks), privilege escalation, or
52 total validation bypass.
53- **2 (Major):** Broken business logic, self-assigned roles, bypass of controls.
54- **3 (Moderate):** PII exposure (e.g., public emails), Inconsistent validation
55 (create vs update) on critical fields
56- **4 (Minor):** Problems that result in self-data corruption like update
57 bypasses that only impact the user's own data, lack of size limits, missing
58 minor type checks or over-permissive read access on non-sensitive fields.
59- **5 (Secure):** Comprehensive validation, strict ownership, and role-based
60 access via secure ACLs.
61 
62Return your assessment in JSON format using the following structure: { "score":
631-5, "summary": "overall assessment", "findings": \[ { "check": "checklist
64item", "severity": "critical|major|moderate|minor", "issue": "description",
65"recommendation": "fix" } \] }

Security

Passed

  • Gen Agent Trust Hubpass
  • Socketpass
  • Snykpass

Preview

firebase/agent-skillsfirebase/agent-skills

$ npx -y skills add firebase/agent-skills --skill firebase-security-rules-auditor

▸ installing to .claude/skills…

✓ firebase-security-rules-auditor ready

Repofirebase/agent-skills
TypeSkills
CategorySecurity
ForDeveloperArchitect
UpdatedJul 2026
License—
First seenJul 26, 2026

Tags

Skill

Related

6 picks
Type
  1. microsoft avatarentra-app-registrationGuides Microsoft Entra ID app registration, OAuth 2.0 authentication, and MSAL integration.SkillsJul 2026484k1.3k
  2. microsoft avatarazure-complianceRun Azure compliance and security audits with azqr plus Key Vault expiration checks.SkillsJul 2026484k1.3k
  3. microsoft avatarentra-agent-idProvision Microsoft Entra Agent Identity Blueprints, BlueprintPrincipals, and per-instance Agent Identities via Microsoft Graph, and configure OAuth 2.0 token…SkillsJul 2026207k1.3k
  4. samber avatargolang-securitySecurity best practices and vulnerability prevention for Golang.SkillsJul 202635k2.7k
  5. googleworkspace avatargws-modelarmorGoogle Model Armor: Filter user-generated content for safety.SkillsJul 202624k30k
  6. googleworkspace avatargws-modelarmor-create-templateGoogle Model Armor: Create a new Model Armor template.SkillsJul 202624k30k