trailofbits-firebase-apk-scanner
Trail of Bits skill scanning Android APKs for Firebase security misconfigurations.
🛡️ AgentReady threat assessment
MAESTRO 7-layer threat model + OWASP AIVSS risk score for trailofbits-firebase-apk-scanner, derived from its capabilities.
These scores are auto-generated from public information (the agent's own listing, docs, and repository) using the canonical OWASP AIVSS formula and the MAESTRO framework — an estimate for guidance, not a penetration test, audit, or certification. See the scoring methodology — every score is re-derived by the same automated method as an agent's public evidence changes.
Overview
Security skill that scans Android APK files for Firebase misconfigurations: open databases, storage buckets, authentication issues, and exposed cloud functions. Unpacks and analyzes APKs via bundled tooling as its script surface.
Key features and capabilities
- APK Firebase misconfig scan
- Open DB/bucket detection
- Exposed cloud-function checks
Use cases
- Mobile app security review
- Firebase exposure hunting