Firebase APK Scanner skill: what it does and how to install it
Scans Android APKs for Firebase security misconfigurations, testing exposed databases, storage, authentication and cloud functions.
Summary generated from the skill's documentation.
Warning. A security audit flagged this skill with a warning. Read its SKILL.md and scripts before you install it.
Install
$ npx skills add trailofbits/skills --skill firebase-apk-scannerRun it in a terminal. If your agent is already running, start a new session so it picks the skill up.
About this skill
What it does. Runs a bundled scanner that decompiles Android APKs, extracts Firebase configuration and probes authentication, databases, storage, cloud functions and Remote Config. It produces text and JSON reports with findings and remediation guidance.
When to use it. For authorised security audits of Android apps that use Firebase. It is not intended for unauthorised testing, non-Android apps or extracting configuration without endpoint testing.
History
Repo stars
7.4kAbout +216 since 9 Jul 2026
Before 1 Oct 2026 the curve is estimated from public event data.
Stars are counted for the whole repository, which holds 49 skills.
Show as a table
| Date | Repo stars |
|---|---|
| 5 Oct 2026 | 7,370 |
| 4 Oct 2026 | 7,355 |
| 3 Oct 2026 | 7,348 |
| 2 Oct 2026 | 7,340 |
| 1 Oct 2026 | 7,320 |
| 24 Sept 2026 (estimated) | 7,310 |
| 17 Sept 2026 (estimated) | 7,305 |
| 10 Sept 2026 (estimated) | 7,239 |
| 3 Sept 2026 (estimated) | 7,179 |
| 27 Aug 2026 (estimated) | 7,174 |
| 20 Aug 2026 (estimated) | 7,174 |
| 13 Aug 2026 (estimated) | 7,169 |
| 6 Aug 2026 (estimated) | 7,164 |
| 30 Jul 2026 (estimated) | 7,164 |
| 23 Jul 2026 (estimated) | 7,164 |
| 16 Jul 2026 (estimated) | 7,164 |
| 9 Jul 2026 (estimated) | 7,154 |
Installs
5.1k
Tracking since . A chart appears once there are 7 days of data.
Installs via skills.sh
Similar skills
- Security and HardeningAudits and hardens code that handles user input, authentication, data storage or external integrations against common vulnerabilities.
- CodeQLScans a codebase for security vulnerabilities with CodeQL's data flow and taint tracking analysis.
- SemgrepRuns a Semgrep security scan: detects languages, selects rulesets, asks for approval, then runs the scans.