Skip to main content

Firebase Apk Scanner

Plugin Verified Active
Part of:Trailofbits

Scan Android APKs for Firebase security misconfigurations including open databases, storage buckets, authentication issues, and exposed cloud functions. For authorized security research only.

1 Skill 0 MCPs
Purpose

To automate the security assessment of Android applications utilizing Firebase, identifying critical misconfigurations that could lead to data breaches or unauthorized access.

Features

  • Decompiles Android APKs
  • Extracts Firebase configuration from multiple sources
  • Tests Firebase authentication, databases, storage, and cloud functions
  • Reports findings with remediation guidance
  • Supports various Android app frameworks (native, React Native, Flutter, Cordova)

Use Cases

  • Audit Android applications for Firebase misconfigurations
  • Test Firebase endpoints extracted from APKs
  • Assess mobile app security involving Firebase backends
  • Perform authorized penetration testing of Firebase-backed applications

Non-Goals

  • Scanning apps without explicit authorization
  • Testing production Firebase projects without written permission
  • Extracting Firebase config without testing
  • Analyzing non-Android targets (iOS, web apps)

Scope

  • info:Dry-run previewThe README mentions a `--no-cleanup` option, which provides some control over modifications, but a full `--dry-run` mode for previewing intended actions is not explicitly documented.

Installation

First, add the marketplace

/plugin marketplace add trailofbits/skills
/plugin install firebase-apk-scanner@trailofbits

Quality Score

Verified
98 /100
Analyzed about 12 hours ago

Trust Signals

Last commit3 days ago
Stars5.2k
LicenseCC-BY-SA-4.0
Status
View Source

© 2025 SkillRepo · Find the right skill, skip the noise.