Back to Skills

firebase-apk-scanner

Scans Android APKs for Firebase security misconfigurations including open databases, storage buckets, authentication issues, and exposed cloud functions. Use when analyzing APK files for Firebase vulnerabilities, performing mobile app security audits, or testing Firebase endpoint security. For authorized security research only.

5,354stars472forksUpdated 5/24/2026

Security Assessment

Safe(100/100)
Security Score100/100

About firebase-apk-scanner

The firebase-apk-scanner skill is designed to analyze Android APK files for Firebase security misconfigurations that could expose backend services, sensitive data, or authentication weaknesses. It automates the process of extracting Firebase configuration details from APKs and testing associated Firebase services for insecure access controls. The skill is intended for authorized mobile application security assessments and helps security professionals identify common Firebase-related vulnerabilities that may otherwise be overlooked during manual analysis.

The skill performs a structured scanning workflow that includes APK decompilation, Firebase configuration extraction, and security testing across multiple Firebase services. It can assess Realtime Database access controls, Firestore exposure, Storage bucket permissions, authentication behaviors such as anonymous access or open signup, Cloud Functions accessibility, and Remote Config exposure. The scanner extracts Firebase-related artifacts from multiple APK sources including configuration files, XML resources, assets, smali code, and DEX strings. It also generates both text and JSON reports to support security reporting and audit workflows.

This skill is primarily intended for penetration testers, mobile application security analysts, red teams, and developers conducting internal security reviews of Firebase-backed Android applications. It is useful during mobile security audits, pre-release security testing, and authorized vulnerability assessments where Firebase infrastructure is part of the application architecture. The skill is specifically designed for Android APK analysis and should only be used in environments where explicit authorization has been granted for testing.

FAQ

What types of Firebase services can this skill test?

The skill can test Firebase Realtime Database, Firestore, Storage buckets, authentication configurations, Cloud Functions, and Remote Config exposure based on the Firebase configuration extracted from Android APK files.

Does this skill work with iOS applications or web applications?

No. The skill is specifically designed for Android APK analysis and is intended only for Firebase-backed Android applications.

What tools or dependencies are required for the scan process?

The workflow relies on tools such as apktool, curl, shell scripts, and file inspection utilities to decompile APKs, extract Firebase configuration, and test Firebase endpoints.

Can the skill extract Firebase configuration without performing security testing?

The documentation recommends using manual extraction methods such as grep or strings when only configuration extraction is needed, since this skill is focused on active security testing and vulnerability assessment.

Are there restrictions on when this skill should be used?

Yes. The skill should only be used for authorized security research, penetration testing, or security audits where explicit permission has been granted to test the target application and Firebase project.

All Files

2 files
SKILL.md6.7 KB
View
references/vulnerabilities.md20.5 KB
View

Install firebase-apk-scanner

Download and extract the skill files to your .claude/skills/ directory.

Quick Setup:

  1. Copy the skill folder to .claude/skills/
  2. Claude will automatically detect and use the skill