Offensive Mobile
SnailSploit/Claude-Red
Mobile (Android + iOS) application penetration testing methodology.
Scans Android APKs for Firebase security misconfigurations such as open databases, storage buckets, weak authentication and exposed cloud functions, for authorized testing only.
$ npx skills add trailofbits/skills --skill firebase-apk-scanner -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install trailofbits/skills firebase-apk-scanner --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/firebase-apk-scanner/skills/firebase-apk-scanner .claude/skills/firebase-apk-scanner && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "firebase-apk-scanner" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/firebase-apk-scanner/skills/firebase-apk-scanner into .claude/skills/firebase-apk-scanner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "firebase-apk-scanner", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/trailofbits/skills/tree/main/plugins/firebase-apk-scanner/skills/firebase-apk-scannerType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add trailofbits/skills --skill firebase-apk-scanner -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install trailofbits/skills firebase-apk-scanner --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/plugins/firebase-apk-scanner/skills/firebase-apk-scanner .agents/skills/firebase-apk-scanner && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "firebase-apk-scanner" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/firebase-apk-scanner/skills/firebase-apk-scanner into .agents/skills/firebase-apk-scanner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "firebase-apk-scanner", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trailofbits/skills --skill firebase-apk-scanner -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install trailofbits/skills firebase-apk-scanner --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/plugins/firebase-apk-scanner/skills/firebase-apk-scanner .cursor/skills/firebase-apk-scanner && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "firebase-apk-scanner" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/firebase-apk-scanner/skills/firebase-apk-scanner into .cursor/skills/firebase-apk-scanner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "firebase-apk-scanner", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/trailofbits/skills.git --path plugins/firebase-apk-scanner/skills/firebase-apk-scanner--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add trailofbits/skills --skill firebase-apk-scanner -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install trailofbits/skills firebase-apk-scanner --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/plugins/firebase-apk-scanner/skills/firebase-apk-scanner .gemini/skills/firebase-apk-scanner && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "firebase-apk-scanner" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/firebase-apk-scanner/skills/firebase-apk-scanner into .gemini/skills/firebase-apk-scanner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "firebase-apk-scanner", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install trailofbits/skills firebase-apk-scannerInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add trailofbits/skills --skill firebase-apk-scanner -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/plugins/firebase-apk-scanner/skills/firebase-apk-scanner .github/skills/firebase-apk-scanner && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "firebase-apk-scanner" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/firebase-apk-scanner/skills/firebase-apk-scanner into .github/skills/firebase-apk-scanner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "firebase-apk-scanner", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add trailofbits/skills --skill firebase-apk-scanner -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install trailofbits/skills firebase-apk-scanner --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/trailofbits/skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/plugins/firebase-apk-scanner/skills/firebase-apk-scanner .opencode/skills/firebase-apk-scanner && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "firebase-apk-scanner" agent skill from https://github.com/trailofbits/skills/tree/main/plugins/firebase-apk-scanner/skills/firebase-apk-scanner into .opencode/skills/firebase-apk-scanner/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "firebase-apk-scanner", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
firebase-apk-scannerScans Android APKs for Firebase security misconfigurations such as open databases, storage buckets, weak authentication and exposed cloud functions, for authorized testing only.
You give the agent an APK file or a folder of them. It confirms the path exists, then runs the bundled scanner.sh script, which works on Firebase endpoints found in the app. The checks cover Realtime Database, Firestore and Storage rules, authentication settings such as open signup, anonymous auth and email enumeration, and Cloud Functions that answer without authentication.
The skill states that it is for authorized security research only: it should not be pointed at apps you lack explicit permission to test, or at production Firebase projects without written permission. It also lists excuses to reject, such as a public API key or an internal-only app, and keeps a references file of vulnerability patterns. It is specific to Android; iOS and web targets are out of scope.
3 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 82fe822. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
Bash({baseDir}/scanner.sh:*)Bash(apktool:*)Bash(curl:*)ReadGrepGlobFrom allowed-tools in the SKILL.md frontmatter.
Ships script files (Shell), which the agent can run.
Shell commands in SKILL.md call:
curlFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
identitytoolkit.googleapis.comfirestore.googleapis.comfirebasestorage.googleapis.comfirebaseremoteconfig.googleapis.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
API_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Firebase APK Security Scanner loads about 1.8k tokens when it runs, and up to ~7.1k if it reads all its reference files. Until then it costs about 88 tokens; SKILL.md has 709 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from trailofbits/skills at commit 82fe822, republished under its CC-BY-SA-4.0 licence (© trailofbits). 709 words, ~1,842 tokens.
.claude/skills/firebase-apk-scanner/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.You are a Firebase security analyst. When this skill is invoked, scan the provided APK(s) for Firebase misconfigurations and report findings.
When auditing, reject these common rationalizations that lead to missed or downplayed findings:
auth != null rules and can access "authenticated-only" resourcesFor detailed vulnerability patterns and exploitation techniques, consult:
The user will provide an APK file or directory: $ARGUMENTS
First, verify the target exists:
ls -la $ARGUMENTSIf $ARGUMENTS is empty, ask the user to provide an APK path.
Execute the bundled scanner script on the target:
{baseDir}/scanner.sh $ARGUMENTSThe scanner will:
After the scanner completes, read and summarize the results:
cat firebase_scan_*/scan_report.txtPresent findings in this format:
| Metric | Value |
|---|---|
| APKs Scanned | X |
| Vulnerable | X |
| Failed to scan | X |
| No Firebase config | X |
| Total Issues | X |
Take these from failed_apks and untested_apks in scan_report.json. Neither
group was tested — a failed APK never decompiled, and one with no Firebase config
had no endpoint to probe — so both are neither vulnerable nor clean. Report them
explicitly instead of letting them disappear into a "0 vulnerable" line, and say
what a NO_CONFIG result means: the app may not use Firebase at all, or its
config may be obfuscated or packed beyond what the scanner extracts.
| Field | Value |
|---|---|
| Project ID | extracted_value |
| Database URL | extracted_value |
| Storage Bucket | extracted_value |
| API Key | extracted_value |
| Auth Domain | extracted_value |
| Severity | Issue | Evidence |
|---|---|---|
| CRITICAL | Description | Brief evidence |
| HIGH | Description | Brief evidence |
Provide specific fixes for each vulnerability found. Reference the Vulnerability Patterns for secure code examples.
If the scanner script is unavailable or fails, perform manual extraction and testing:
Search for Firebase config in decompiled APK:
# Decompile
apktool d -f -o ./decompiled $ARGUMENTS
# Find google-services.json
find ./decompiled -name "google-services.json"
# Search XML resources
grep -r "firebaseio.com\|appspot.com\|AIza" ./decompiled/res/
# Search assets (hybrid apps)
grep -r "firebaseio.com\|AIza" ./decompiled/assets/Once you have the PROJECT_ID and API_KEY:
Authentication:
# Test open signup
curl -s -X POST -H "Content-Type: application/json" \
-d '{"email":"test@test.com","password":"Test123!","returnSecureToken":true}' \
"https://identitytoolkit.googleapis.com/v1/accounts:signUp?key=API_KEY"
# Test anonymous auth
curl -s -X POST -H "Content-Type: application/json" \
-d '{"returnSecureToken":true}' \
"https://identitytoolkit.googleapis.com/v1/accounts:signUp?key=API_KEY"Database:
# Realtime Database read
curl -s "https://PROJECT_ID.firebaseio.com/.json"
# Firestore read
curl -s "https://firestore.googleapis.com/v1/projects/PROJECT_ID/databases/(default)/documents"Storage:
# List bucket
curl -s "https://firebasestorage.googleapis.com/v0/b/PROJECT_ID.appspot.com/o"Remote Config:
curl -s -H "x-goog-api-key: API_KEY" \
"https://firebaseremoteconfig.googleapis.com/v1/projects/PROJECT_ID/remoteConfig"© trailofbits, CC-BY-SA-4.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 4 other files (references, assets) in plugins/firebase-apk-scanner/skills/firebase-apk-scanner of trailofbits/skills.
Open the folder on GitHubat commit 82fe822
Firebase APK Security Scanner next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Firebase APK Security Scanner this skilltrailofbits/skills | 7.4k | — | ~1.8k | Automated safety check: Pass | CC-BY-SA-4.0 | |
| Offensive MobileSnailSploit/Claude-Red | 7.3k | — | ~3.5k | Automated safety check: Pass | MIT | |
| Exposed MigrationGerardPaligot/Confily | 152 | — | ~1.3k | Automated safety check: Pass | Apache-2.0 | |
| Kotlin LintingGerardPaligot/Confily | 152 | — | ~708 | Automated safety check: Pass | Apache-2.0 | |
| Post Edit VerificationGerardPaligot/Confily | 152 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | |
| Android APK Pentesterptn1411/skill | 219 | — | ~917 | Automated safety check: Pass | None |
SnailSploit/Claude-Red
Mobile (Android + iOS) application penetration testing methodology.
GerardPaligot/Confily
A skill your agent uses when adding, removing, or modifying columns, indexes, or tables in any Exposed table object (files under infrastructure/exposed/ ending in Table.kt).
GerardPaligot/Confily
A skill your agent uses whenever you write or modify Kotlin files in this project.
GerardPaligot/Confily
Use this skill after every working session where Kotlin or Android code was created or modified, and ALWAYS before committing, opening a PR, or reporting work as done.
ptn1411/skill
Runs a full workflow for authorized Android app security testing: static APK analysis, rooted emulator setup, traffic interception and Frida hook generation.
mukul975/Anthropic-Cybersecurity-Skills
Performs runtime dynamic analysis of Android applications using Frida, Objection, and Android Debug Bridge to observe application behavior during execution, intercept function calls, modify runtime…
trailofbits/skills
Generates Mermaid diagrams from Trailmark code graphs, including call graphs, class hierarchies, module dependency maps, complexity heatmaps and attack surface data flows.
trailofbits/skills
Scans a codebase for vulnerabilities with CodeQL's data flow and taint tracking in run-all or important-only modes, including data extensions for project-specific sources and sinks.
trailofbits/skills
Compares Trailmark code graphs at two snapshots, such as commits, tags or directories, to surface attack paths, blast radius and taint changes that text diffs miss.
trailofbits/skills
Draws a 12 Houses tarot spread to break ties when a request is vague or casually delegated, then reads the cards to pick the next step.
trailofbits/skills
Searches and extracts data from Burp Suite project files on the command line: regex searches over responses, audit findings, proxy history and site map data.
trailofbits/skills
Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.
Works with
Scans Android APKs for Firebase security misconfigurations such as open databases, storage buckets, weak authentication and exposed cloud functions, for authorized testing only. You give the agent an APK file or a folder of them.sh script, which works on Firebase endpoints found in the app.
Firebase APK Security Scanner fits situations like: auditing an Android app for Firebase security misconfigurations; checking whether Firebase endpoints found in an APK allow unauthenticated access; enumerating Cloud Functions during an authorized penetration test; running a mobile security assessment of a Firebase-backed app.
Run `npx skills add trailofbits/skills --skill firebase-apk-scanner -a claude-code`. Or copy the skill folder (plugins/firebase-apk-scanner/skills/firebase-apk-scanner in trailofbits/skills) into .claude/skills/firebase-apk-scanner in your project. Claude Code loads it when a task matches its description.
Run `npx skills add trailofbits/skills --skill firebase-apk-scanner -a codex`. Or copy the skill folder (plugins/firebase-apk-scanner/skills/firebase-apk-scanner in trailofbits/skills) into .agents/skills/firebase-apk-scanner in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add trailofbits/skills --skill firebase-apk-scanner -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/firebase-apk-scanner, .gemini/skills/firebase-apk-scanner, .github/skills/firebase-apk-scanner and .opencode/skills/firebase-apk-scanner in your project.
Going by SKILL.md and its folder, Firebase APK Security Scanner needs a shell for the scripts in its folder, the command-line tools its instructions call (curl) and credentials named API_KEY. Our summary lists: apktool and curl; An APK file or directory to scan; Explicit authorization to test the target app. Its frontmatter pre-approves these tools: Bash({baseDir}/scanner.sh:*), Bash(apktool:*), Bash(curl:*), Read, Grep, Glob.
SKILL.md names 4 domains. In commands or code: identitytoolkit.googleapis.com, firestore.googleapis.com, firebasestorage.googleapis.com and firebaseremoteconfig.googleapis.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Firebase APK Security Scanner is published under the CC-BY-SA-4.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.8k tokens (SKILL.md is roughly 7.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.3k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Firebase APK Security Scanner: Offensive Mobile (SnailSploit/Claude-Red, 7.3k stars), Exposed Migration (GerardPaligot/Confily, 152 stars), Kotlin Linting (GerardPaligot/Confily, 152 stars) and Post Edit Verification (GerardPaligot/Confily, 152 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
trailofbits (a GitHub organization, an official publisher) maintains it in trailofbits/skills, which has 7,420 GitHub stars. The repository holds 79 skills in this directory. The repository was last updated on October 7, 2026.
Source: trailofbits/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.