Firebase APK security scanner: find misconfigured backends
Decompile an Android APK, extract its Firebase config and probe Realtime Database, Firestore, Storage and Cloud Functions for misconfigurations — authorized testing only
- What
- Decompile an Android APK, extract its Firebase config and probe Realtime Database, Firestore, Storage and Cloud Functions for misconfigurations — authorized testing only
- Cost
- Free
- Needs
- Bash with apktool installed; an Android APK you own or have explicit written authorization to test — AUTHORIZED USE ONLY / USAGE AUTORISÉ UNIQUEMENT
- Install
- Copy the installer prompt below into your Muse — your agent does the rest.
Curated by Skill Harbor — ⚠️ **Security warning / Avertissement de sécurité — AUTHORIZED USE ONLY / USAGE AUTORISÉ UNIQUEMENT** : @trailofbits' Firebase APK scanner for mobile security audits — decompile an Android APK with apktool, extract its Firebase configuration (google-services.json, XML resources, assets, smali/DEX strings) and probe it: authentication endpoints (open signup, anonymous auth, email enumeration), Realtime Database and Firestore read/write access, Storage bucket listing, Cloud Function enumeration, Remote Config exposure, with severity-classified reports in text and JSON plus remediation guidance. By @trailofbits, listed here with credit to its creator. Kept by editorial choice as a borderline case: the skill itself demands authorization, rejects rationalizations that downplay findings, and says to clean up test data. Honest caveats: dual-use — scanning apps you have no permission to test is out of scope and may be illegal; APK-specific (Android only); CC-BY-SA-4.0 licensed. Skill Harbor never reviews the code, review it yourself before use. Discovered via skills.sh.
Version:
Install
Prerequisites: Bash with apktool installed; an Android APK you own or have explicit written authorization to test — AUTHORIZED USE ONLY / USAGE AUTORISÉ UNIQUEMENT Install "Firebase APK security scanner: find misconfigured backends" for me. It scans Android APKs for Firebase security misconfigurations — decompiling the APK, extracting its Firebase config and probing Realtime Database, Firestore, Storage and Cloud Functions — for authorized security testing only. Repository: https://github.com/trailofbits/skills/blob/main/plugins/firebase-apk-scanner/skills/firebase-apk-scanner/SKILL.md 1. Fetch the SKILL.md file (and any helper files) from the repository path into a temporary folder and summarize what it does in one or two sentences. 2. Safety check: review the SKILL.md and scripts for anything suspicious (unexpected network calls, shell commands, credential harvesting). This repo should contain zero secrets in code, credentials only via the secure vault, allowed hosts declared in the SKILL.md. Verify that holds here; STOP on any red flag and tell me. 3. Install it as a skill: copy SKILL.md and its helper files into the agent's skills directory, in a folder named "firebase-apk-scanner". 4. Verify with no network calls: frontmatter valid, files in place. 5. Report what was installed, where, and what I still need to do myself (e.g. install apktool; never point it at an app you have no permission to test — authorized use only). GitHub is optional: if I have a GitHub account or the gh CLI, you may use it; otherwise public access is fine. Never require it unless it's in the prerequisites above. Rules: don't touch anything outside the temp folder and the install target. If anything looks off, stop and ask me.
Questions
How do I install a build?
Every product page includes a copy-paste install prompt. Paste it into your Muse and it sets the build up for you — no manual configuration.
Where does my money go?
Straight to the seller. Skill Harbor never processes payments: checkout happens on the seller’s own page, usually Stripe.
What does the ✓ next to a creator’s name mean?
It means we confirmed the identity of the person behind the listing. It says nothing about the code itself — always check a build before installing it.