Skills
Skill 11 of 13
Audits Firebase (Firestore, Cloud Storage) security rules for vulnerabilities, privilege escalation, role bypasses, create vs update inconsistencies, resource exhaustion, type…
2 minutes · 462 words · 6 sections
Install
npx skills add firebase/agent-skills --skill firebase-security-rules-auditornpx skills add firebase/agent-skills/plugin marketplace add firebase/agent-skillsThe first command installs just this skill, by the name in its SKILL.md; the second installs the whole repository.
This skill acts as an auditor for Firebase Security Rules, evaluating them against a rigorous set of criteria to ensure they are secure, robust, and correctly implemented.
You are a Senior Security Auditor and Penetration Tester specializing in Firestore. Your goal is to find “the hole in the wall.” Do not assume a rule is secure because it looks complex; instead, actively try to find a sequence of operations to bypass it.
hasOnly() or diff(). While these restrict which fields can be
updated, they do NOT restrict who can update them unless an ownership check
(e.g., resource.data.uid == request.auth.uid) is also present. If a rule
allows any authenticated user to update fields on another user’s document
without a corresponding ownership check, it is a data integrity
vulnerability.The admin bootstrapping process is limited in this app. If the rules use a single hardcoded admin email (e.g., checking request.auth.token.email == ‘admin@example.com (opens in a new tab)‘), this should NOT count against the score as long as:
Return your assessment in JSON format using the following structure:
{
"score": 1,
"summary": "overall assessment",
"findings": [
{
"check": "checklist item",
"severity": "critical|major|moderate|minor",
"issue": "description",
"recommendation": "fix"
}
]
}Audits Firebase (Firestore, Cloud Storage) security rules for vulnerabilities, privilege escalation, role bypasses, create vs update inconsistencies, resource exhaustion, type safety, size limits, and hasOnly ownership checks. Use when auditing/reviewing rules, running red-team rule assessments, or scoring against auditor checklists. Don't use for Firebase CLI (login, deploy), Auth, Crashlytics, Remote Config, or database queries.
The verbatim description from this skill’s front matter — the string an agent matches on to decide whether to load it.
main, last pushed 23 September 2026.SKILL.md, not by matching a directory convention. One layout observed: skills/*/SKILL.md.h1 and no skipped levels:.claude-plugin/marketplace.json by Firebase, declaring 1 plugin. It is read for editorial metadata only — never as the skill index, which is always the repository tree./firebase/agent-skills.md, and each skill at its own .md URL.