From file to useful result
How to ask with this skill installed
Installing the skill gives your AI a method. Your request still has to provide the case-specific facts, constraints and expected output.
Describe the decision or deliverable, not just the topic.
Add source material, audience, limits and known facts.
Set format, quality criteria and checks.
When to use it
- Auditing Android applications for Firebase security misconfigurations
- Testing Firebase endpoints extracted from APKs (Realtime Database, Firestore, Storage)
- Checking authentication security (open signup, anonymous auth, email enumeration)
- Enumerating Cloud Functions and testing for unauthenticated access
- Mobile app security assessments involving Firebase backends
- Authorized penetration testing of Firebase-backed applications
When not to use it
- Scanning apps you do not have explicit authorization to test
- Testing production Firebase projects without written permission
- When you only need to extract Firebase config without testing (use manual grep/strings instead)
- For non-Android targets (iOS, web apps) - this skill is APK-specific
- When the target app does not use Firebase