Skip to content

chore(deps): update firebase/agent-skills digest to 02c0a61#653

Merged
rdimitrov merged 4 commits into
mainfrom
renovate/firebase-agent-skills-digest
Jun 3, 2026
Merged

chore(deps): update firebase/agent-skills digest to 02c0a61#653
rdimitrov merged 4 commits into
mainfrom
renovate/firebase-agent-skills-digest

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented May 13, 2026

This PR contains the following updates:

Package Update Change
firebase/agent-skills digest c3bb9d502c0a61

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • Between 12:00 AM and 03:59 AM, only on Monday (* 0-3 * * 1)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

…g-genkit-go,developing-genkit-js,firebase-ai-logic-basics,firebase-app-hosting-basics,firebase-auth-basics,firebase-basics,firebase-data-connect-basics,firebase-firestore,firebase-hosting-basics,firebase-security-rules-auditor
@renovate
Copy link
Copy Markdown
Contributor Author

renovate Bot commented May 13, 2026

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

@toolhive-release-app
Copy link
Copy Markdown
Contributor

toolhive-release-app Bot commented May 13, 2026

🛡️ Skill Security Scan Results

✅ developing-genkit-dart

  • Status: Passed
  • Findings: 5
  • Allowed (not blocking): 3
    • MANIFEST_MISSING_LICENSE (Allowed: firebase/agent-skills is licensed Apache-2.0 at the repository root; upstream does not embed an SPDX license identifier in per-skill SKILL.md frontmatter.)
    • PIPELINE_TAINT_FLOW (Allowed: The skill's prerequisites cite the official Genkit CLI installer curl -sL cli.genkit.dev | bash as a documented install command.)
    • ATR_2026_00111 (Allowed: FP: same root cause as PIPELINE_TAINT_FLOW / ATR_MCP_MALICIOUS_RESPONSE
      above - cisco-ai-skill-scanner matched the '| bash' fragment of the
      official Genkit CLI installer curl -sL cli.genkit.dev | bash cited as
      a documented prerequisite (SKILL.md:17). The host (cli.genkit.dev) is
      the official Google Genkit installer endpoint. Hard-coded skill
      instruction text, not an executable threat. firebase/agent-skills @02c0a61.
      )

✅ developing-genkit-go

  • Status: Passed
  • Findings: 0

✅ developing-genkit-js

  • Status: Passed
  • Findings: 5
  • Allowed (not blocking): 1
    • MANIFEST_MISSING_LICENSE (Allowed: firebase/agent-skills is licensed Apache-2.0 at the repository root; upstream does not embed an SPDX license identifier in per-skill SKILL.md frontmatter.)

✅ firebase-ai-logic-basics

  • Status: Passed
  • Findings: 4
  • Allowed (not blocking): 1
    • MANIFEST_MISSING_LICENSE (Allowed: firebase/agent-skills is licensed Apache-2.0 at the repository root; upstream does not embed an SPDX license identifier in per-skill SKILL.md frontmatter.)

✅ firebase-app-hosting-basics

  • Status: Passed
  • Findings: 4
  • Allowed (not blocking): 1
    • MANIFEST_MISSING_LICENSE (Allowed: firebase/agent-skills is licensed Apache-2.0 at the repository root; upstream does not embed an SPDX license identifier in per-skill SKILL.md frontmatter.)

✅ firebase-auth-basics

  • Status: Passed
  • Findings: 4
  • Allowed (not blocking): 1
    • MANIFEST_MISSING_LICENSE (Allowed: firebase/agent-skills is licensed Apache-2.0 at the repository root; upstream does not embed an SPDX license identifier in per-skill SKILL.md frontmatter.)

✅ firebase-basics

  • Status: Passed
  • Findings: 2

✅ firebase-data-connect-basics

  • Status: Passed
  • Findings: 160
  • Allowed (not blocking): 76
    • ATR_2026_00012 (Allowed: FP: cisco-ai-skill-scanner matched GraphQL/SQL example syntax (named variables $id/$key, UPDATE/DELETE example statements); no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00012 (Allowed: FP: cisco-ai-skill-scanner matched GraphQL/SQL example syntax (named variables $id/$key, UPDATE/DELETE example statements); no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00111 (Allowed: FP: cisco-ai-skill-scanner matched SDK API method names in docs ('subscribe()', 'execute()', 'executeQuery', 'id: UUID!'); no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00111 (Allowed: FP: cisco-ai-skill-scanner matched SDK API method names in docs ('subscribe()', 'execute()', 'executeQuery', 'id: UUID!'); no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00012 (Allowed: FP: cisco-ai-skill-scanner matched GraphQL/SQL example syntax (named variables $id/$key, UPDATE/DELETE example statements); no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00012 (Allowed: FP: cisco-ai-skill-scanner matched GraphQL/SQL example syntax (named variables $id/$key, UPDATE/DELETE example statements); no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00012 (Allowed: FP: cisco-ai-skill-scanner matched GraphQL/SQL example syntax (named variables $id/$key, UPDATE/DELETE example statements); no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00051 (Allowed: FP: cisco-ai-skill-scanner matched documentation prose ('for each'); no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00010 (Allowed: FP: cisco-ai-skill-scanner matched documentation prose/code examples (GraphQL operation/filter descriptions, 'default' branch text); no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00010 (Allowed: FP: cisco-ai-skill-scanner matched documentation prose/code examples (GraphQL operation/filter descriptions, 'default' branch text); no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00012 (Allowed: FP: cisco-ai-skill-scanner matched GraphQL/SQL example syntax (named variables $id/$key, UPDATE/DELETE example statements); no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00004 (Allowed: FP: cisco-ai-skill-scanner matched documentation prose (markdown headers like '# Admin', '### Configuration'); no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00040 (Allowed: FP: cisco-ai-skill-scanner matched word fragments 'exec'/'Exec' (from execute/Exec) and 'deploy'/'Deploy' in documentation; no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00040 (Allowed: FP: cisco-ai-skill-scanner matched word fragments 'exec'/'Exec' (from execute/Exec) and 'deploy'/'Deploy' in documentation; no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00010 (Allowed: FP: cisco-ai-skill-scanner matched documentation prose/code examples (GraphQL operation/filter descriptions, 'default' branch text); no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00004 (Allowed: FP: cisco-ai-skill-scanner matched documentation prose (markdown headers like '# Admin', '### Configuration'); no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00066 (Allowed: FP: cisco-ai-skill-scanner matched documentation code-fence markers ('`bash') and template-literal example syntax (${...}); no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00040 (Allowed: FP: cisco-ai-skill-scanner matched word fragments 'exec'/'Exec' (from execute/Exec) and 'deploy'/'Deploy' in documentation; no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00111 (Allowed: FP: cisco-ai-skill-scanner matched SDK API method names in docs ('subscribe()', 'execute()', 'executeQuery', 'id: UUID!'); no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00040 (Allowed: FP: cisco-ai-skill-scanner matched word fragments 'exec'/'Exec' (from execute/Exec) and 'deploy'/'Deploy' in documentation; no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00013 (Allowed: FP: cisco-ai-skill-scanner matched local emulator addresses in docs (10.0.2.2, 127.0.0.1:9399); no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00040 (Allowed: FP: cisco-ai-skill-scanner matched word fragments 'exec'/'Exec' (from execute/Exec) and 'deploy'/'Deploy' in documentation; no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00040 (Allowed: FP: cisco-ai-skill-scanner matched word fragments 'exec'/'Exec' (from execute/Exec) and 'deploy'/'Deploy' in documentation; no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00040 (Allowed: FP: cisco-ai-skill-scanner matched word fragments 'exec'/'Exec' (from execute/Exec) and 'deploy'/'Deploy' in documentation; no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00066 (Allowed: FP: cisco-ai-skill-scanner matched documentation code-fence markers ('`bash') and template-literal example syntax (${...}); no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00066 (Allowed: FP: cisco-ai-skill-scanner matched documentation code-fence markers ('`bash') and template-literal example syntax (${...}); no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00040 (Allowed: FP: cisco-ai-skill-scanner matched word fragments 'exec'/'Exec' (from execute/Exec) and 'deploy'/'Deploy' in documentation; no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00040 (Allowed: FP: cisco-ai-skill-scanner matched word fragments 'exec'/'Exec' (from execute/Exec) and 'deploy'/'Deploy' in documentation; no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00040 (Allowed: FP: cisco-ai-skill-scanner matched word fragments 'exec'/'Exec' (from execute/Exec) and 'deploy'/'Deploy' in documentation; no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00010 (Allowed: FP: cisco-ai-skill-scanner matched documentation prose/code examples (GraphQL operation/filter descriptions, 'default' branch text); no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00066 (Allowed: FP: cisco-ai-skill-scanner matched documentation code-fence markers ('`bash') and template-literal example syntax (${...}); no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00040 (Allowed: FP: cisco-ai-skill-scanner matched word fragments 'exec'/'Exec' (from execute/Exec) and 'deploy'/'Deploy' in documentation; no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00040 (Allowed: FP: cisco-ai-skill-scanner matched word fragments 'exec'/'Exec' (from execute/Exec) and 'deploy'/'Deploy' in documentation; no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00040 (Allowed: FP: cisco-ai-skill-scanner matched word fragments 'exec'/'Exec' (from execute/Exec) and 'deploy'/'Deploy' in documentation; no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00066 (Allowed: FP: cisco-ai-skill-scanner matched documentation code-fence markers ('`bash') and template-literal example syntax (${...}); no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00040 (Allowed: FP: cisco-ai-skill-scanner matched word fragments 'exec'/'Exec' (from execute/Exec) and 'deploy'/'Deploy' in documentation; no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00040 (Allowed: FP: cisco-ai-skill-scanner matched word fragments 'exec'/'Exec' (from execute/Exec) and 'deploy'/'Deploy' in documentation; no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00040 (Allowed: FP: cisco-ai-skill-scanner matched word fragments 'exec'/'Exec' (from execute/Exec) and 'deploy'/'Deploy' in documentation; no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00040 (Allowed: FP: cisco-ai-skill-scanner matched word fragments 'exec'/'Exec' (from execute/Exec) and 'deploy'/'Deploy' in documentation; no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00013 (Allowed: FP: cisco-ai-skill-scanner matched local emulator addresses in docs (10.0.2.2, 127.0.0.1:9399); no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00040 (Allowed: FP: cisco-ai-skill-scanner matched word fragments 'exec'/'Exec' (from execute/Exec) and 'deploy'/'Deploy' in documentation; no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00040 (Allowed: FP: cisco-ai-skill-scanner matched word fragments 'exec'/'Exec' (from execute/Exec) and 'deploy'/'Deploy' in documentation; no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00040 (Allowed: FP: cisco-ai-skill-scanner matched word fragments 'exec'/'Exec' (from execute/Exec) and 'deploy'/'Deploy' in documentation; no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00040 (Allowed: FP: cisco-ai-skill-scanner matched word fragments 'exec'/'Exec' (from execute/Exec) and 'deploy'/'Deploy' in documentation; no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00040 (Allowed: FP: cisco-ai-skill-scanner matched word fragments 'exec'/'Exec' (from execute/Exec) and 'deploy'/'Deploy' in documentation; no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00040 (Allowed: FP: cisco-ai-skill-scanner matched word fragments 'exec'/'Exec' (from execute/Exec) and 'deploy'/'Deploy' in documentation; no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00010 (Allowed: FP: cisco-ai-skill-scanner matched documentation prose/code examples (GraphQL operation/filter descriptions, 'default' branch text); no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00010 (Allowed: FP: cisco-ai-skill-scanner matched documentation prose/code examples (GraphQL operation/filter descriptions, 'default' branch text); no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00066 (Allowed: FP: cisco-ai-skill-scanner matched documentation code-fence markers ('`bash') and template-literal example syntax (${...}); no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00111 (Allowed: FP: cisco-ai-skill-scanner matched SDK API method names in docs ('subscribe()', 'execute()', 'executeQuery', 'id: UUID!'); no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00040 (Allowed: FP: cisco-ai-skill-scanner matched word fragments 'exec'/'Exec' (from execute/Exec) and 'deploy'/'Deploy' in documentation; no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00040 (Allowed: FP: cisco-ai-skill-scanner matched word fragments 'exec'/'Exec' (from execute/Exec) and 'deploy'/'Deploy' in documentation; no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00040 (Allowed: FP: cisco-ai-skill-scanner matched word fragments 'exec'/'Exec' (from execute/Exec) and 'deploy'/'Deploy' in documentation; no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00040 (Allowed: FP: cisco-ai-skill-scanner matched word fragments 'exec'/'Exec' (from execute/Exec) and 'deploy'/'Deploy' in documentation; no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00111 (Allowed: FP: cisco-ai-skill-scanner matched SDK API method names in docs ('subscribe()', 'execute()', 'executeQuery', 'id: UUID!'); no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00040 (Allowed: FP: cisco-ai-skill-scanner matched word fragments 'exec'/'Exec' (from execute/Exec) and 'deploy'/'Deploy' in documentation; no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00040 (Allowed: FP: cisco-ai-skill-scanner matched word fragments 'exec'/'Exec' (from execute/Exec) and 'deploy'/'Deploy' in documentation; no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00040 (Allowed: FP: cisco-ai-skill-scanner matched word fragments 'exec'/'Exec' (from execute/Exec) and 'deploy'/'Deploy' in documentation; no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00088 (Allowed: FP: cisco-ai-skill-scanner matched documentation prose/code examples; no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00010 (Allowed: FP: cisco-ai-skill-scanner matched documentation prose/code examples (GraphQL operation/filter descriptions, 'default' branch text); no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00012 (Allowed: FP: cisco-ai-skill-scanner matched GraphQL/SQL example syntax (named variables $id/$key, UPDATE/DELETE example statements); no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00012 (Allowed: FP: cisco-ai-skill-scanner matched GraphQL/SQL example syntax (named variables $id/$key, UPDATE/DELETE example statements); no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00012 (Allowed: FP: cisco-ai-skill-scanner matched GraphQL/SQL example syntax (named variables $id/$key, UPDATE/DELETE example statements); no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00111 (Allowed: FP: cisco-ai-skill-scanner matched SDK API method names in docs ('subscribe()', 'execute()', 'executeQuery', 'id: UUID!'); no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00040 (Allowed: FP: cisco-ai-skill-scanner matched word fragments 'exec'/'Exec' (from execute/Exec) and 'deploy'/'Deploy' in documentation; no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00040 (Allowed: FP: cisco-ai-skill-scanner matched word fragments 'exec'/'Exec' (from execute/Exec) and 'deploy'/'Deploy' in documentation; no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00012 (Allowed: FP: cisco-ai-skill-scanner matched GraphQL/SQL example syntax (named variables $id/$key, UPDATE/DELETE example statements); no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00040 (Allowed: FP: cisco-ai-skill-scanner matched word fragments 'exec'/'Exec' (from execute/Exec) and 'deploy'/'Deploy' in documentation; no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00004 (Allowed: FP: cisco-ai-skill-scanner matched documentation prose (markdown headers like '# Admin', '### Configuration'); no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00040 (Allowed: FP: cisco-ai-skill-scanner matched word fragments 'exec'/'Exec' (from execute/Exec) and 'deploy'/'Deploy' in documentation; no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00040 (Allowed: FP: cisco-ai-skill-scanner matched word fragments 'exec'/'Exec' (from execute/Exec) and 'deploy'/'Deploy' in documentation; no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00066 (Allowed: FP: cisco-ai-skill-scanner matched documentation code-fence markers ('`bash') and template-literal example syntax (${...}); no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00040 (Allowed: FP: cisco-ai-skill-scanner matched word fragments 'exec'/'Exec' (from execute/Exec) and 'deploy'/'Deploy' in documentation; no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00040 (Allowed: FP: cisco-ai-skill-scanner matched word fragments 'exec'/'Exec' (from execute/Exec) and 'deploy'/'Deploy' in documentation; no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00161 (Allowed: FP: cisco-ai-skill-scanner matched documentation prose/code examples; no executable threat. firebase/agent-skills @02c0a61.)
    • ATR_2026_00040 (Allowed: FP: cisco-ai-skill-scanner matched word fragments 'exec'/'Exec' (from execute/Exec) and 'deploy'/'Deploy' in documentation; no executable threat. firebase/agent-skills @02c0a61.)

✅ firebase-firestore

  • Status: Passed
  • Findings: 3

✅ firebase-hosting-basics

  • Status: Passed
  • Findings: 4
  • Allowed (not blocking): 1
    • MANIFEST_MISSING_LICENSE (Allowed: firebase/agent-skills is licensed Apache-2.0 at the repository root; upstream does not embed an SPDX license identifier in per-skill SKILL.md frontmatter.)

✅ firebase-security-rules-auditor

  • Status: Passed
  • Findings: 2
  • Allowed (not blocking): 1
    • MANIFEST_MISSING_LICENSE (Allowed: firebase/agent-skills is licensed Apache-2.0 at the repository root; upstream does not embed an SPDX license identifier in per-skill SKILL.md frontmatter.)

Summary: Scanned 11 skill(s), all passed security checks. ✅

JAORMX and others added 2 commits June 3, 2026 09:55
…0a61

The firebase/agent-skills digest bump to 02c0a61 trips cisco-ai-skill-scanner
ATR_2026_* rules on benign reference documentation. All blocking findings are
false positives (word-fragment/substring matches on docs prose, GraphQL/SQL
code examples, SDK API names, emulator IPs, and a documented MCP server config).
Suppress the exact blocking rule_ids per skill via security.allowed_issues.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
…installer

Updated cisco-ai-skill-scanner rule pack now also fires ATR_2026_00111
(CRITICAL) on the '| bash' fragment of the official Genkit CLI installer
`curl -sL cli.genkit.dev | bash` documented as a prerequisite (SKILL.md:17).
Same benign root cause as the existing PIPELINE_TAINT_FLOW allowlist entry.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
@rdimitrov rdimitrov merged commit 3bab07e into main Jun 3, 2026
40 checks passed
@rdimitrov rdimitrov deleted the renovate/firebase-agent-skills-digest branch June 3, 2026 09:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants