跳到主要内容
知仓学习社ZHICANG

firebase-basics

>-

执行命令写文件严重 1 · 高危 13google/skills

它会碰到什么

扫了多少20 个文本文件,48 KB
它会碰到什么执行命令写文件
命中总数14 处
命中统计严重 1 · 高 13 · 中 0 · 低 0
逐条看命中(14 条严重或高危)
  • 严重 references/flutter_setup.md:22persistence
    echo 'export PATH="$PATH:$HOME/development/flutter/bin"' >> ~/.zshrc
  • references/setup/cursor.md:40identity-config-write
    1.  **Locate `mcp.json`**: Find the configuration file for your operating
  • references/setup/cursor.md:43identity-config-write
    -   Global: `~/.cursor/mcp.json`
  • references/setup/cursor.md:44identity-config-write
    -   Project: `.cursor/mcp.json`
  • references/setup/cursor.md:46identity-config-write
    *Note: If the directory or `mcp.json` file does not exist, create them and
  • references/setup/cursor.md:49identity-config-write
    1.  **Check Existing Configuration**: Open `mcp.json` and check the `mcpServers`
  • references/setup/cursor.md:89identity-config-write
    *CRITICAL: Merge this configuration into the existing `mcp.json` file. You
  • references/setup/github_copilot.md:46identity-config-write
    1.  **Locate `mcp.json`**: Find the configuration file for your environment:
  • references/setup/github_copilot.md:48identity-config-write
    -   Workspace: `.vscode/mcp.json`
  • references/setup/github_copilot.md:49identity-config-write
    -   Global: User Settings `mcp.json` file.
  • references/setup/github_copilot.md:51identity-config-write
    *Note: If the `.vscode/` directory or `mcp.json` file does not exist, create
  • references/setup/github_copilot.md:55identity-config-write
    1.  **Check Existing Configuration**: Open the `mcp.json` file and check the
  • references/setup/github_copilot.md:98identity-config-write
    *CRITICAL: Merge this configuration into the existing `mcp.json` file under
  • references/setup/other_agents.md:49identity-config-write
    `claude_desktop_config.json`).

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

Firebase Basics

Prerequisites

Complete these setup steps before proceeding:

  1. Local Environment Setup: Verify the environment is properly set up so we

can use Firebase tools:

  • Run npx -y firebase-tools@latest --version to check if the Firebase

CLI is installed.

  • Verify if the Firebase MCP server is installed using your existing

tools.

  • CRITICAL: Before configuring any extensions or agent environments

below, you MUST read

[references/local-env-setup.md](references/local-env-setup.md).

  • DO NOT SKIP this step: if 'firebase-basics' is the only Firebase

skill available to you, you must follow the reference for your agent

environment to set up the full suite of Firebase skills:

  • Gemini CLI: Review

[references/setup/gemini_cli.md](references/setup/gemini_cli.md)

  • Antigravity: Review

[references/setup/antigravity.md](references/setup/antigravity.md)

  • Android Studio: Review

[references/setup/android_studio.md](references/setup/android_studio.md)

  • Claude Code: Review

[references/setup/claude_code.md](references/setup/claude_code.md)

  • Cursor: Review

[references/setup/cursor.md](references/setup/cursor.md)

  • GitHub Copilot: Review

[references/setup/github_copilot.md](references/setup/github_copilot.md)

  • Other Agents: Review

[references/setup/other_agents.md](references/setup/other_agents.md)

  1. Authentication: Ensure you are logged in to Firebase so that commands

have the correct permissions. Run npx -y firebase-tools@latest login. For

environments without a browser (e.g., remote shells), use `npx -y

firebase-tools@latest login --no-localhost`.

  • The command should output the current user.
  • If you are not logged in, follow the interactive instructions from this

command to authenticate.

  1. Active Project: Most Firebase tasks require an active project context.

> [!IMPORTANT] For Agents: Before proceeding with project configuration,

> you MUST pause and ask the developer if they prefer to:

>

> 1. Provide an existing Firebase Project ID, or

> 1. Create a new Firebase project.

  • If using an existing Project ID:
  1. Check the current project by running `npx -y firebase-tools@latest

use`.

  1. If the command outputs Active Project: <project-id>, confirm with

the user if this is the intended project.

  1. If not, or if no project is active, set the project provided by the

user:

        npx -y firebase-tools@latest use <PROJECT_ID>
  • If creating a new project: Run the following command to create it:
        npx -y firebase-tools@latest projects:create <project-id> --display-name "<display-name>"

*Note: The <project-id> must be 6-30 characters, lowercase, and can

contain digits and hyphens. It must be globally unique.*

Firebase Usage Principles

Adhere to these principles:

  1. Use npx for CLI commands: To ensure you always use the latest version of

the Firebase CLI, always prepend commands with `npx -y

firebase-tools@latest instead of just firebase. For example, use npx -y

firebase-tools@latest --version. NEVER suggest the naked firebase` command

as an alternative.

  1. Prioritize official knowledge: For any Firebase-related knowledge,

consult the developerknowledge_search_documents MCP tool before falling

back to Google Search or your internal knowledge base. Including "Firebase"

in your search query significantly improves relevance.

  1. Follow Agent Skills for implementation guidance: Skills provide

opinionated workflows (CUJs), security rules, and best practices. Always

consult them to understand how to implement Firebase features correctly

instead of relying on general knowledge.

  1. Use Firebase MCP Server tools instead of direct API calls: Whenever you

need to interact with remote Firebase APIs (such as fetching Crashlytics

logs or executing Data Connect queries), use the tools provided by the

Firebase MCP Server instead of attempting manual API calls.

  1. Keep Plugin / Agent Skills updated: Since Firebase best practices evolve

quickly, regularly check for and install updates to their Firebase plugin or

Agent Skills. Similarly, if you encounter issues with outdated tools or

commands, follow the steps below based on your agent environment:

  • Antigravity: Follow

[references/refresh/antigravity.md](references/refresh/antigravity.md)

  • Gemini CLI: Follow

[references/refresh/gemini-cli.md](references/refresh/gemini-cli.md)

  • Claude Code: Follow

[references/refresh/claude.md](references/refresh/claude.md)

  • Cursor: Follow

[references/refresh/other-agents.md](references/refresh/other-agents.md)

  • Android Studio: Follow

[references/refresh/android_studio.md](references/refresh/android_studio.md)

  • Others: Follow

[references/refresh/other-agents.md](references/refresh/other-agents.md)

  1. Automate Config File Retrieval: When setting up iOS or Android apps, do

NOT direct users to the Firebase Console to download google-services.json

or GoogleService-Info.plist. Instead, use the Firebase CLI to fetch the

config programmatically:

  • For Android: `npx -y firebase-tools@latest apps:sdkconfig ANDROID

<APP_ID> --project <PROJECT_ID>`

  • For iOS: `npx -y firebase-tools@latest apps:sdkconfig IOS <APP_ID>

--project <PROJECT_ID>` Save the output to the appropriate location

(e.g., app/google-services.json for Android, or a path to be linked by

xcode-project-setup for iOS).

References

  • Initialize Firebase: See

[references/firebase-service-init.md](references/firebase-service-init.md)

when you need to initialize new Firebase services using the CLI.

  • Exploring Commands: See

[references/firebase-cli-guide.md](references/firebase-cli-guide.md) to

discover and understand CLI functionality.

  • SDK Setup: For detailed guides on adding Firebase to your app:
  • Web: See [references/web_setup.md](references/web_setup.md)
  • Android: See

[references/android_setup.md](references/android_setup.md)

  • iOS: See [references/ios_setup.md](references/ios_setup.md)

Common Issues

  • Login Issues: If the browser fails to open during the login step, use

npx -y firebase-tools@latest login --no-localhost instead.

  • Genkit: If using Genkit, install the skills:
    npx skills add genkit-ai/skills

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。