Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsBlogPro
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges
  • Chrome Extension
  • Skill Manager

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Firebase Apk Scanner

ASecurity

当需要审计 Android APK 的 Firebase 后端安全配置时使用;反编译 APK、提取 Firebase 配置并测试 Auth/数据库/存储/云函数/Remote Config 端点,产出漏洞与修复清单;不适用于无授权目标、iOS/Web 应用或仅提取配置不测试的场景;触发词:firebase apk 扫描、apk firebase 漏洞、firebase 安全审计、firebaseio 数据库、firestore 越权、storage bucket、cloud functions、mobile security audit

3 stars
0 votes
0 copies
1 views
Added 9/19/2026
ai-agentsgobashapidatabasebackendsecurity

Works with

cursorcliapi

Security Analysis

A92/100
mediumUses curl or wget to download content

Pro shows the line behind each finding and how to fix it

Scanned 9/19/2026

$npx -y skills add findscripter/everything-skills --skill firebase-apk-scanner --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Firebase Apk Scanner?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Firebase Apk Scanner
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/findscripter-firebase-apk-scanner/badge)](https://www.skillsdirectory.com/skills/findscripter-firebase-apk-scanner)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
Files
SKILL.md
---
name: firebase-apk-scanner
title: Android APK Firebase 配置扫描
description: 当需要审计 Android APK 的 Firebase 后端安全配置时使用;反编译 APK、提取 Firebase 配置并测试 Auth/数据库/存储/云函数/Remote Config 端点,产出漏洞与修复清单;不适用于无授权目标、iOS/Web 应用或仅提取配置不测试的场景;触发词:firebase apk 扫描、apk firebase 漏洞、firebase 安全审计、firebaseio 数据库、firestore 越权、storage bucket、cloud functions、mobile security audit
domain: 安全/ops
triggers: [firebase apk 扫描, apk firebase 漏洞, firebase 安全审计, firebaseio 数据库, firestore 越权, storage bucket, cloud functions, mobile security audit]
tags: [security, firebase, apk, android, mobile, pentest, ops]
level: 进阶
status: stable
agents: [claude-code, codex, cursor, gemini-cli]
tools: [apktool, curl, scanner.sh, Bash, Grep, Glob, Read]
requires: []
related: [cloud-misconfig-auditor, api-fuzzing-bug-bounty, firmware-reverse-analyst, insecure-defaults-detector]
combines_with: [firebase-backend, cloud-misconfig-auditor, api-fuzzing-bug-bounty]
license: CC-BY-SA-4.0
source: trailofbits/skills
source_license: CC-BY-SA-4.0
---
## 何时使用

适用于在**已获授权**的前提下,审计 Android 应用的 Firebase 后端安全配置:

- 反编译 APK,提取 Firebase 配置并测试 Realtime Database、Firestore、Storage 端点
- 检查认证安全:开放注册(open signup)、匿名认证、邮箱枚举
- 枚举 Cloud Functions 并测试未授权访问
- 检查 Remote Config 是否公开暴露

**不该用的边界(务必遵守):**

- 没有明确书面授权的目标——禁止扫描
- 未经许可的生产 Firebase 项目——禁止测试
- 仅需提取配置而不测试端点——改用手动 `grep`/`strings` 即可
- iOS、Web 等非 Android 目标——本技能仅针对 APK
- 目标应用根本不使用 Firebase

**拒绝以下导致漏报/降级的借口:** "数据库只读所以没事"(PII/密钥仍可能泄露);"只是匿名认证"(匿名 token 仍能绕过 `auth != null` 规则);"API Key 本就公开"(公开 Key 不能为开放规则开脱);"里面没敏感数据"(未来会存,规则不安全本身就是漏洞);"是内网 App"(APK 可从任意设备提取);"上线前会修"(务必记录,预发漏洞常带到生产)。

## 步骤

1. **校验输入**:确认目标 APK 文件或目录存在;若未提供路径,向用户索要。
2. **运行扫描器**:执行随附的 `scanner.sh`,它会自动完成反编译、提取配置、测试各端点并生成文本/JSON 报告。
3. **呈现结果**:读取 `firebase_scan_*/scan_report.txt`,按"扫描概要 / 提取的配置 / 发现的漏洞(含严重级别与证据)/ 修复建议"汇总。
4. **扫描器不可用时**:按下方"指令"手动反编译、提取配置、逐端点测试。

## 指令

校验与扫描:

```bash
ls -la $ARGUMENTS
{baseDir}/scanner.sh $ARGUMENTS
cat firebase_scan_*/scan_report.txt
```

手动反编译与配置提取(PROJECT_ID、API_KEY 等):

```bash
apktool d -f -o ./decompiled $ARGUMENTS
find ./decompiled -name "google-services.json"
grep -r "firebaseio.com\|appspot.com\|AIza" ./decompiled/res/
grep -r "firebaseio.com\|AIza" ./decompiled/assets/
```

API Key 格式:`AIza[A-Za-z0-9_-]{35}`;提取位置含 `google-services.json`(client[].api_key[].current_key)、`res/values/strings.xml`、`assets/*.json`、smali `const-string`、DEX strings。

端点测试(拿到 PROJECT_ID / API_KEY 后):

```bash
# 认证:开放注册
curl -s -X POST -H "Content-Type: application/json" \
  -d '{"email":"test@test.com","password":"Test123!","returnSecureToken":true}' \
  "https://identitytoolkit.googleapis.com/v1/accounts:signUp?key=API_KEY"

# 认证:匿名认证
curl -s -X POST -H "Content-Type: application/json" \
  -d '{"returnSecureToken":true}' \
  "https://identitytoolkit.googleapis.com/v1/accounts:signUp?key=API_KEY"

# 认证:邮箱枚举(registered 字段会泄露注册状态)
curl -s -X POST -H "Content-Type: application/json" \
  -d '{"identifier":"victim@company.com","continueUri":"https://localhost"}' \
  "https://identitytoolkit.googleapis.com/v1/accounts:createAuthUri?key=API_KEY"

# Realtime Database 读(.json / shallow 探结构)
curl -s "https://PROJECT_ID.firebaseio.com/.json"
curl -s "https://PROJECT_ID.firebaseio.com/.json?shallow=true"
# Realtime Database 写(测试后务必清理)
curl -s -X PUT -H "Content-Type: application/json" \
  -d '{"attacker":"was_here"}' "https://PROJECT_ID.firebaseio.com/_security_test.json"

# Firestore 文档
curl -s "https://firestore.googleapis.com/v1/projects/PROJECT_ID/databases/(default)/documents"

# Storage:列桶(.appspot.com 与裸桶名都试)
curl -s "https://firebasestorage.googleapis.com/v0/b/PROJECT_ID.appspot.com/o"

# Cloud Functions(多 region:us-central1/europe-west1/asia-east1 等)
curl -s "https://us-central1-PROJECT_ID.cloudfunctions.net/functionName"

# Remote Config
curl -s -H "x-goog-api-key: API_KEY" \
  "https://firebaseremoteconfig.googleapis.com/v1/projects/PROJECT_ID/remoteConfig"
```

Cloud Functions 响应码判定:404=不存在,401/403=存在且受保护,200=可访问。

## 示例

某 APK 中提取到 `projectId=demo-app`、`AIzaSy...`。运行扫描器后报告显示:

- **CRITICAL**:`curl https://demo-app.firebaseio.com/.json` 返回完整 `users` 节点(含 email/phone)——Realtime Database 未授权读。
- **HIGH**:匿名注册返回 `idToken`——匿名认证开启,可用该 token 绕过 `auth != null` 规则访问"仅登录"资源。
- **MEDIUM**:`createAuthUri` 对已知邮箱回 `registered:true`——邮箱枚举。

修复方向:数据库规则改为默认 `false` 并按 `$uid === auth.uid` 授权;关闭注册或限制为 Admin SDK;开启 User enumeration protection;Storage/Firestore 默认拒绝、按用户目录授权。

## 注意事项

1. **必须授权**:仅扫描你有权限测试的 APK。
2. **清理测试数据**:扫描器会自动删除其写入的测试条目;手动测试写入后也要手动清除。
3. **保存 token**:匿名认证成功后,用返回的 token 做认证绕过测试。
4. **测试所有 region**:Cloud Functions 可能部署在 us-central1、europe-west1、asia-east1 等。
5. **多实例**:部分应用使用多个 Firebase 项目,测试所有发现的配置。
6. **严重级别**:CRITICAL=未授权数据库读写/存储写/私有应用开放注册;HIGH=匿名认证/桶列举/集合枚举;MEDIUM=邮箱枚举/可访问云函数/Remote Config 暴露;LOW=无敏感数据的信息泄露。

## 互见

详细漏洞模式、利用手法与安全规则范例参见源仓库 references/vulnerabilities.md(涵盖 12 类问题与安全规则写法)。

---

本条采编自 trailofbits/skills(CC-BY-SA-4.0)。

Attribution

findscripterfindscripter
View sourceSee grades on GitHubMore from findscripter →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Terse caveman voice: answer first, fluff gone, every technical fact kept. Use for /caveman, "caveman mode", "talk like caveman", "be brief", "less tokens". Stays on until "stop caveman" or "normal mode".

1100021 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

698431 votes

Writing Skills

Create and manage Claude Code skills in HASH repository following Anthropic best practices. Use when creating new skills, modifying skill-rules.json, understanding trigger patterns, working with hooks, debugging skill activation, or implementing progressive disclosure. Covers skill structure, YAML frontmatter, trigger types (keywords, intent patterns), UserPromptSubmit hook, and the 500-line rule. Includes validation and debugging with SKILL_DEBUG. Examples include rust-error-stack, cargo-dep...

3931 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3421 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Amp, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Grok Build, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

741 votes
View all in ai-agents →