Claude Code skills · updated 2026-10-03

Firestore security rules skill for Claude Code — open paths, missing auth

10 findings in one firestore.rules file, each with the path a client can reach

firestore-rules-security-check - findings on the bundled example

On the bundled sample: 10 findings (3 errors, 3 warnings, 4 info) in 1 file from 13 rules, including test mode denied since 2026-08-20.

Get it on Whop - $12 onceGet it on Gumroad

Who it's for

Firebase developers who keep firestore.rules or storage.rules in git - often first drafted in test mode or by a coding assistant - and are about to launch.

What breaks, and when

With allow ... : if true the path is open to anyone on the internet with your project ID. Once a test-mode date passes, every client read and write is denied.

What it printed on the bundled example

== Firestore Security Rules Lint — 10 findings (3 errors, 3 warnings, 4 info) in 1 file · 13 rules
  WARN  firestore-sample.rules:1  [rules_version_missing]
        This file has no rules_version = '2' line, so Firebase evaluates it with version 1 semantics and the recursive wildcard behaves differently than the code you read.
  ERROR firestore-sample.rules:6  [testmode_expired]
        Test mode expired: every client read and write under this path is being denied, so the app is failing for real users. Denied since 2026-08-20 (44 days ago). Path: /databases/{database}/documents/{document=**}.
  INFO  firestore-sample.rules:10  [list_exposure]
        read covers both get and list — a client can page the entire collection. Split into get and list if only single-document reads are intended. Path: /databases/{database}/documents/users/{userId}.
  ERROR firestore-sample.rules:11  [owner_check_missing]
        The path captures a user id but the condition never compares it to request.auth.uid, so one customer can write another customer's document. Path: /databases/{database}/documents/users/{userId}.

What you get

Install

Unzip into ~/.claude/skills/ (all projects) or your-repo/.claude/skills/ (one repo), then ask Claude Code: "We're launching our Firebase app next week. Can one user read or overwrite another user's data with our current rules? Don't edit anything yet.". Needs Node 16+.

unzip firestore-rules-security-check.zip -d ~/.claude/skills/

Ask Claude

“We're launching our Firebase app next week. Can one user read or overwrite another user's data with our current rules? Don't edit anything yet.”

What it does not do

It does not connect to Firebase or evaluate helper functions; it reads *.rules text only. No network calls, no edits without your OK.

FAQ

What is a Claude Code skill?

A folder with a SKILL.md and scripts that Claude Code loads when your request matches it. You ask in plain words and Claude runs the scanner the skill carries.

How is this different from asking Claude without the skill?

The skill carries a dated rule table and a scanner that reads every file, so Claude quotes the exact date and line instead of answering from memory.

Does it send my code anywhere?

It does not connect to Firebase or evaluate helper functions; it reads *.rules text only. No network calls, no edits without your OK.

How do I install it?

Unzip into ~/.claude/skills/ (all projects) or your-repo/.claude/skills/ (one repo), then ask Claude Code: "We're launching our Firebase app next week. Can one user read or overwrite another user's data with our current rules? Don't edit anything yet.". Needs Node 16+.

What do I get when I buy?

The zip. On Whop it is in your library as a download lesson with the zip attached; on Gumroad it is the product file.