Skip to content
appsgit

Firebase Security Rules Auditor

Firebase Security Rules Auditor is an agent skill (a SKILL.md file) from firebase/agent-skills. Audits Firebase (Firestore, Cloud Storage) security rules for vulnerabilities, privilege escalation, role bypasses, create vs update inconsistencies, resource exhaustion, type safety… It works with Claude Code, Codex, Cursor, Gemini CLI and GitHub Copilot and has 462 GitHub stars across a repository of 9 listed skills.

github.com/firebase/agent-skills/skills/firebase-security-rules-auditor (opens in a new tab)

  • Official
  • Multi-skill repo
  • Plugin marketplace
  • Security
  • Actively maintained

Add this skill

Claude

This repository is a Claude Code plugin marketplace. In Claude Code:

/plugin marketplace add firebase/agent-skills
/plugin install firebase@firebase

In the Claude apps, zip the firebase-security-rules-auditor folder and upload it under Customize > Skills > + > Upload a skill (code execution must be on).

ChatGPT / Codex

Codex reads skills from .agents/skills/ in a repo or ~/.agents/skills/ for every project:

git clone --depth 1 https://github.com/firebase/agent-skills.git
cp -r agent-skills/skills/firebase-security-rules-auditor .agents/skills/firebase-security-rules-auditor   # repo; ~/.agents/skills for all projects

Standalone skills also load in the ChatGPT desktop app.

Cursor

Cursor loads skills from .cursor/skills/ (or ~/.cursor/skills/) and also reads .claude/skills/:

git clone --depth 1 https://github.com/firebase/agent-skills.git
cp -r agent-skills/skills/firebase-security-rules-auditor .cursor/skills/firebase-security-rules-auditor   # project; ~/.cursor/skills for all projects

Source (checked Oct 7, 2026): code.claude.com/docs/en/skills (opens in a new tab), code.claude.com/docs/en/plugin-marketplaces (opens in a new tab), support.claude.com/en/articles/12512180-using-skills-in-claude (opens in a new tab), learn.chatgpt.com/docs/build-skills (opens in a new tab), cursor.com/docs/context/skills (opens in a new tab)

What this skill does

Audits Firebase (Firestore, Cloud Storage) security rules for vulnerabilities, privilege escalation, role bypasses, create vs update inconsistencies, resource exhaustion, type safety, size limits, and hasOnly ownership checks. Use when auditing/reviewing rules, running red-team rule assessments, or scoring against auditor checklists. Don't use for Firebase CLI (login, deploy), Auth, Crashlytics, Remote Config, or database queries.

When it triggers

  • Use when auditing/reviewing rules, running red-team rule assessments, or scoring against auditor checklists.
  • use for Firebase CLI (login, deploy), Auth, Crashlytics, Remote Config, or database queries.

More skills in firebase/agent-skills

9 skills are listed from this repository.

FAQ

Firebase Security Rules Auditor FAQ

Still curious? Email info@appsgit.com.

What is the Firebase Security Rules Auditor skill?

Firebase Security Rules Auditor is an agent skill (a SKILL.md file) from firebase/agent-skills. Audits Firebase (Firestore, Cloud Storage) security rules for vulnerabilities, privilege escalation, role bypasses, create vs update inconsistencies, resource exhaustion, type safety… It works with Claude Code, Codex, Cursor, Gemini CLI and GitHub Copilot and has 462 GitHub stars across a repository of 9 listed skills. Its SKILL.md lives at github.com/firebase/agent-skills/skills/firebase-security-rules-auditor.

How do I install the Firebase Security Rules Auditor skill?

In Claude Code, run /plugin marketplace add firebase/agent-skills and then /plugin install firebase@firebase. For Codex or Cursor, copy the firebase-security-rules-auditor folder into .agents/skills/ or .cursor/skills/.

Is the Firebase Security Rules Auditor skill free?

Yes. The repository is open source under the Apache-2.0 license.

Is Firebase Security Rules Auditor maintained?

The repository's most recent commit was on Oct 6, 2026. appsgit only lists skills from repositories with a commit in the last six months.