Setup & Installation
What This Skill Does
Scans Android APKs for Firebase security misconfigurations by decompiling the app, extracting Firebase configuration, and actively testing endpoints for vulnerabilities. Checks Realtime Database, Firestore, Storage buckets, Cloud Functions, and authentication settings for unauthenticated access and weak rules. Reports findings with severity ratings and remediation guidance.
Manual Firebase testing requires decompiling APKs, locating config across multiple file formats, and constructing curl requests for each service — this skill automates the full chain from APK to structured vulnerability report.
When to use it
- Auditing a mobile app's Firebase database for unauthenticated read/write access
- Testing whether anonymous auth tokens can bypass Firebase security rules
- Checking if Firebase Storage buckets allow public listing or writes
- Extracting and validating Firebase config from a third-party APK during a pentest
- Enumerating Cloud Functions in a Firebase project for unauthenticated endpoints