# Firebase Security Rules Auditor (agent skill)

> Firebase Security Rules Auditor is an agent skill (a SKILL.md file) from firebase/agent-skills. Audits Firebase (Firestore, Cloud Storage) security rules for vulnerabilities, privilege escalation, role bypasses, create vs update inconsistencies, resource exhaustion, type safety… It works with Claude Code, Codex, Cursor, Gemini CLI and GitHub Copilot and has 462 GitHub stars across a repository of 9 listed skills.

Audits Firebase (Firestore, Cloud Storage) security rules for vulnerabilities, privilege escalation, role bypasses, create vs update inconsistencies, resource exhaustion, type safety, size limits, and hasOnly ownership checks. Use when auditing/reviewing rules, running red-team rule assessments, or scoring against auditor checklists. Don't use for Firebase CLI (login, deploy), Auth, Crashlytics, Remote Config, or database queries.

## Key facts

| Fact | Value |
|---|---|
| Repository | https://github.com/firebase/agent-skills |
| Skill path | skills/firebase-security-rules-auditor/SKILL.md |
| Skill name | firebase-security-rules-auditor |
| GitHub stars | 462 |
| Installs on skills.sh | 128,520 |
| License | Apache-2.0 |
| Skills in repo | 9 |
| Plugin marketplace | firebase |
| Official | yes |
| Works with | Claude Code, Codex, Cursor, Gemini CLI, GitHub Copilot |
| Category | Security |
| Last commit | Oct 6, 2026 |

## When it triggers

- Use when auditing/reviewing rules, running red-team rule assessments, or scoring against auditor checklists.
- use for Firebase CLI (login, deploy), Auth, Crashlytics, Remote Config, or database queries.

## Add this skill

### Claude Code

```sh
/plugin marketplace add firebase/agent-skills
/plugin install firebase@firebase
```

In the Claude apps, zip the skill folder and upload it under Customize > Skills > + > Upload a skill (code execution must be on).

### ChatGPT / Codex

```sh
git clone --depth 1 https://github.com/firebase/agent-skills.git
cp -r agent-skills/skills/firebase-security-rules-auditor .agents/skills/firebase-security-rules-auditor   # repo; ~/.agents/skills for all projects
```

### Cursor

```sh
git clone --depth 1 https://github.com/firebase/agent-skills.git
cp -r agent-skills/skills/firebase-security-rules-auditor .cursor/skills/firebase-security-rules-auditor   # project; ~/.cursor/skills for all projects
```

Sources (checked 2026-10-07): https://code.claude.com/docs/en/skills, https://support.claude.com/en/articles/12512180-using-skills-in-claude, https://learn.chatgpt.com/docs/build-skills, https://cursor.com/docs/context/skills

skills.sh listing: https://www.skills.sh/firebase/agent-skills/firebase-security-rules-auditor

---

Canonical page: https://appsgit.com/skills/firebase-security-rules-auditor
Source: appsgit (https://appsgit.com), the app store for github. Data from the GitHub API, refreshed nightly.
Machine access: JSON API https://appsgit.com/api/v1/apps (OpenAPI: https://appsgit.com/openapi.json), MCP server https://mcp.appsgit.com/mcp, full index https://appsgit.com/llms-full.txt.
