The skill misrepresents itself as an active Firebase security rules
Claims to do
Overview: This skill acts as an auditor for Firebase Security Rules, evaluating them against a rigorous set of criteria to ensure they are secure, robust, and correctly implemented.
Actually does
The skill provides detailed instructions to an AI model on how to perform a security audit of Firebase Security Rules. It defines a mandatory checklist, scoring criteria, and an output JSON format for the AI's assessment. It does not call any external tools, access external data, run commands, or contact URLs.
/plugin marketplace add firebase/agent-skills/plugin install firebase-security-rules-auditor@firebase/agent-skillsgemini extensions install https://github.com/firebase/agent-skills.git --consentnpx skills add https://github.com/firebase/agent-skills --skill firebase-security-rules-auditorThe skill's stated purpose is to 'act as an auditor,' implying direct execution or interaction with Firebase. However, the skill content only provides instructions for an AI model to perform an audit, without any executable code, API calls, or external tool integrations. It is a prompt, not an active auditor.
The skill content consists solely of instructions, checklists, and output format definitions for an AI model, with no code, API calls, or external resource interactions.
[](https://mondoo.com/ai-agent-security/skills/github/firebase/agent-skills/firebase-security-rules-auditor)<a href="https://mondoo.com/ai-agent-security/skills/github/firebase/agent-skills/firebase-security-rules-auditor"><img src="https://mondoo.com/ai-agent-security/api/badge/github/firebase/agent-skills/firebase-security-rules-auditor.svg" alt="Mondoo Skill Check" /></a>https://mondoo.com/ai-agent-security/api/badge/github/firebase/agent-skills/firebase-security-rules-auditor.svgSkills can read files, run commands, and access credentials. Mondoo helps organizations manage the security risks of AI agent skills across their entire fleet.