AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Security Privacy

skill-gdvega-super-android-kotlin-firebase-skill-security-privacy · by GDvega

Use for Android and Firebase security, secrets, API keys, Firebase Security Rules, local encryption, biometrics, least privilege, privacy-first data handling and sensitive data reviews.

No reviews yet
0 installs
29 views
0.0% view→install

Install

$ agentstack add skill-gdvega-super-android-kotlin-firebase-skill-security-privacy

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-gdvega-super-android-kotlin-firebase-skill-security-privacy)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
2mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Security Privacy? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Purpose

Reduce real security and privacy risks in Android/Firebase apps.

When to use

  • Auditing sensitive data handling.
  • Reviewing Firebase rules.
  • Checking secrets, logs or permissions.
  • Adding biometric or local encryption flows.

Inputs to inspect

  • Data classification and threat model.
  • Rules files and storage paths.
  • Logs, analytics and Crashlytics usage.
  • Permissions and local storage.

Required workflow

  1. Classify data and trust boundaries.
  2. Search for secrets and sensitive logs.
  3. Review Firebase rules and Android permissions.
  4. Propose least-privilege fixes.
  5. Add tests or manual verification steps.

Rules

  • Never exfiltrate or print secrets.
  • No open production rules.
  • Do not rely on client-only authorization.
  • Do not log PII, tokens or sensitive health/financial data.
  • Use encryption only with a clear threat model.

Related existing skills

Local skills to invoke

  • firebase-core
  • firestore
  • firebase-auth
  • code-review-refactor
  • testing

External companion skills to use when installed

Do not assume these companion skills are installed. Prefer the local skills above first, then consult [Companion Skills](../../docs/COMPANION_SKILLS.md) for install and verification commands.

  • firebase/agent-skills — use for deeper Firebase product, Firestore, Security Rules or emulator workflow guidance when installed.

Files commonly touched

  • firestore.rules
  • database.rules.json
  • storage.rules
  • AndroidManifest.xml
  • logging/analytics code
  • local storage code

Commands to validate

git grep -n "apiKey\|secret\|password\|token"
firebase emulators:exec "npm test"
./gradlew lint
./gradlew test

Common mistakes to avoid

  • Putting private keys in BuildConfig.
  • Treating Firebase API keys as authorization.
  • Logging user identifiers unnecessarily.
  • Opening rules for convenience.

Checklist

  • Secrets not committed.
  • Rules least-privilege.
  • Logs safe.
  • Permissions minimal.
  • Risks documented.

Example prompts

  • Use $super-android-kotlin-firebase to audit Firestore and Storage rules.
  • Use $super-android-kotlin-firebase to check this app for secret leaks.

Expected response style

Respond with: brief diagnosis, change plan, affected files, code or diff summary, validation commands, tests added or recommended, risks, and next step. For review tasks, lead with findings ordered by severity.

References

  • ../../docs/audits/FUENTES_LOCALES.md
  • references/android-firebase-security.md
  • templates/security-review-template.md

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.