AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Firebase Messaging

skill-gdvega-super-android-kotlin-firebase-skill-firebase-messaging · by GDvega

Use for Firebase Cloud Messaging, tokens, notifications, data messages, Android 13+ notification permission, foreground/background handling and push testing.

No reviews yet
0 installs
39 views
0.0% view→install

Install

$ agentstack add skill-gdvega-super-android-kotlin-firebase-skill-firebase-messaging

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-gdvega-super-android-kotlin-firebase-skill-firebase-messaging)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
2mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Firebase Messaging? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Purpose

Integrate push messaging with clear permissions, safe payloads and testable token handling.

When to use

  • Adding FCM notifications or data messages.
  • Managing device tokens.
  • Handling POST_NOTIFICATIONS permission.
  • Debugging foreground/background push behavior.

Inputs to inspect

  • Message type and target audience.
  • Payload shape and sensitivity.
  • Token lifecycle code.
  • Permission UX and backend sender.

Required workflow

  1. Define notification vs data message behavior.
  2. Add token storage/update strategy.
  3. Add contextual notification permission flow.
  4. Handle foreground/background display.
  5. Test token refresh and message delivery states.

Rules

  • Do not put sensitive data in push payloads.
  • Do not assume tokens are permanent.
  • Handle Android 13+ notification permission.
  • Avoid duplicate notifications.
  • Document backend and topic risks.

Related existing skills

Local skills to invoke

  • firebase-core
  • firebase-cloud-functions
  • security-privacy
  • ui-state-design

External companion skills to use when installed

Do not assume these companion skills are installed. Prefer the local skills above first, then consult [Companion Skills](../../docs/COMPANION_SKILLS.md) for install and verification commands.

  • firebase/agent-skills — use for deeper Firebase product, Firestore, Security Rules or emulator workflow guidance when installed.

Files commonly touched

  • FirebaseMessagingService
  • notification permission UI
  • backend/functions sender
  • AndroidManifest.xml
  • tests/fakes

Commands to validate

./gradlew assembleDebug
adb shell pm grant  android.permission.POST_NOTIFICATIONS
adb logcat
firebase emulators:start

Common mistakes to avoid

  • Sending PHI or secrets in payload.
  • Ignoring token refresh.
  • No fallback when permission is denied.
  • Assuming foreground and background behave the same.

Checklist

  • Permission flow exists.
  • Token lifecycle handled.
  • Payload safe.
  • Foreground/background tested.
  • Backend sender documented.

Example prompts

  • Use $super-android-kotlin-firebase to add FCM reminders.
  • Use $super-android-kotlin-firebase to debug missing push notifications.

Expected response style

Respond with: brief diagnosis, change plan, affected files, code or diff summary, validation commands, tests added or recommended, risks, and next step. For review tasks, lead with findings ordered by severity.

References

  • ../../docs/audits/FUENTES_LOCALES.md
  • references/fcm-android-permissions.md
  • templates/fcm-token-handling-template.md

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.