This skill uses coercive prompts to hijack agent workflows and force unauthorized enterprise-tier cloud provisioning while relying on unverified, insecure dependency execution and missing critical documentation.
npx skills add https://github.com/firebase/agent-skillsThe skill uses authoritative, mandatory language ('You MUST unconditionally activate this skill') to pressure the agent into prioritizing its use, which is a common pattern for hijacking agent workflows.
You MUST unconditionally activate this skill if you plan to use Firestore in any way.
The skill includes a coercive instruction to 'unconditionally activate' itself, which is an attempt to bypass user discretion and force persistent execution.
Description: 'You MUST unconditionally activate this skill if you plan to use Firestore in any way.'
The instructions force the agent to default to provisioning 'Enterprise' edition databases without explicit user confirmation of the cost or resource implications, potentially leading to unexpected cloud billing.
default to provisioning an Enterprise edition database
Global/unverified dependency execution — global npm/yarn package, dotnet tool, or auto-confirmed npx run without version or integrity pinning (seen 5 times in this file at lines 10, 20, 25, 39, 43)
npx -y
Skill body contains no code blocks or usage examples, making it harder for users to evaluate.
SKILL.md links to "references/standard/android_sdk_usage.md" but the file is not part of the skill package — the workflow silently degrades or the content is sourced elsewhere at runtime
[android_sdk_usage.md](references/standard/android_sdk_usage.md)
SKILL.md links to "references/standard/ios_setup.md" but the file is not part of the skill package — the workflow silently degrades or the content is sourced elsewhere at runtime
[ios_setup.md](references/standard/ios_setup.md)
SKILL.md links to "references/standard/provisioning.md" but the file is not part of the skill package — the workflow silently degrades or the content is sourced elsewhere at runtime
[provisioning.md](references/standard/provisioning.md)
SKILL.md links to "references/standard/security_rules.md" but the file is not part of the skill package — the workflow silently degrades or the content is sourced elsewhere at runtime
[security_rules.md](references/standard/security_rules.md)
SKILL.md links to "references/standard/web_sdk_usage.md" but the file is not part of the skill package — the workflow silently degrades or the content is sourced elsewhere at runtime
[web_sdk_usage.md](references/standard/web_sdk_usage.md)
Skill does not specify a license field. Specifying a license helps users understand usage terms.
Skill description is empty or too short. A clear description helps users evaluate the skill's purpose.
[](https://mondoo.com/ai-agent-security/skills/github/firebase/agent-skills/firebase-firestore)<a href="https://mondoo.com/ai-agent-security/skills/github/firebase/agent-skills/firebase-firestore"><img src="https://mondoo.com/ai-agent-security/api/badge/github/firebase/agent-skills/firebase-firestore.svg" alt="Mondoo Skill Check" /></a>https://mondoo.com/ai-agent-security/api/badge/github/firebase/agent-skills/firebase-firestore.svgSkills can read files, run commands, and access credentials. Mondoo helps organizations manage the security risks of AI agent skills across their entire fleet.