firebase-security-rules-auditor
Firebase security rules auditor
firebase-security-rules-auditor is the Firebase team's agent skill for auditing Firestore and Cloud Storage security rules for privilege escalation, update bypasses and missing limits, returning a 1 to 5 score in JSON.
Install Firebase security rules auditor
Install this skill with the skills CLI
npx skills add firebase/agent-skills --skill firebase-security-rules-auditorOr, in Gemini CLI, install the Firebase extension
gemini extensions install https://github.com/firebase/skillsOr, for Claude Code, add the Firebase plugin marketplace
claude plugin marketplace add firebase/skillsThen install the firebase plugin
claude plugin install firebase@firebaseFirebase's README also documents Codex (codex plugin marketplace add firebase/skills, then codex plugin add firebase@firebase) and Kimi Code CLI. The README uses the older repository name firebase/skills, which GitHub redirects to firebase/agent-skills.
Or paste this into your coding agent: Install the agent skill firebase-security-rules-auditor from github.com/firebase/agent-skills.
A skill can include scripts that run on your computer, so read its source first.
What Firebase security rules auditor does
firebase-security-rules-auditor is an agent skill from the Firebase team at Google that has the agent act as a red-team auditor of Firebase security rules. Instead of assuming complex rules are safe, the agent tries to find a sequence of reads and writes that gets around them. The checklist and examples are written around Firestore, although the skill's description also names Cloud Storage rules.
The firebase-security-rules-auditor checklist has six items. Could a user write a valid document first and later edit it into an invalid state, for example by granting themselves a role? Do rules trust user-supplied fields like role, isAdmin or ownerId? Do the rules still let the app work? Are there size limits on strings and arrays? Are field types checked? Do hasOnly or diff checks also verify who is making the change?
The result is JSON with a score from 1, critical, to 5, secure, a summary and a list of findings with severity and a fix for each. A single hardcoded admin email does not lower the score if email verification is checked and no one can promote themselves. The skill is short, about 540 words, and has no scripts or emulator tests.
When to use Firebase security rules auditor
- You wrote Firestore security rules and want them attacked before launch.
- You suspect users can change their own role or another user's document.
- You want a scored audit of your rules you can track over time.
- An AI tool generated your Firebase rules and you want them checked.
When to pick something else
- Writing new rules from scratch: use firestore-rules-creation from the same repository.
- Firebase CLI deploys, Auth setup or database queries: the skill says it does not cover those.
Which agents Firebase security rules auditor works in
Firebase (Google) documents Firebase security rules auditor for Gemini CLI, Claude Code, Codex, Kimi Code CLI, Cursor, Windsurf, GitHub Copilot. The open skills CLI also installs it into 78 agents, including Claude Code, Codex, Cursor, Gemini CLI, GitHub Copilot, OpenCode (we listed it with the CLI on October 1, 2026). See where each agent looks for skills.
Firebase security rules auditor license
Firebase security rules auditor is published under Apache-2.0.
Related skills for security
- Differential review: differential-review is Trail of Bits' agent skill for security review of a pull request, commit or diff, using git history, blast radius counts and test coverage, and ending in a written markdown report.
- GitHub Actions security review: gha-security-review is Sentry's agent skill for auditing GitHub Actions workflows for attacks an outsider can run, such as pwn requests, expression injection and credential theft, with a concrete exploit for each finding.
- Security review: security-review is Sentry's agent skill for reviewing code for exploitable vulnerabilities, such as injection, XSS, broken access control and weak crypto, reporting only findings it has confirmed with high confidence.
- Semgrep rule creator: semgrep-rule-creator is Trail of Bits' agent skill for writing custom Semgrep rules that detect vulnerabilities and bug patterns, test-first, with taint mode preferred and every test required to pass.