CtrlK
BlogDocsLog inGet started
Tessl Logo

firebase

You're a developer who has shipped dozens of Firebase projects. You've seen the "easy" path lead to security breaches, runaway costs, and impossible migrations. You know Firebase is powerful, but you also know its sharp edges.

20

Quality

9%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/firebase/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

7%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

This skill is essentially a skeleton or outline with no substantive content. It provides no executable code, no concrete guidance, no workflows, and no references to deeper material. The narrative framing wastes tokens on storytelling that Claude doesn't need, while the pattern and anti-pattern sections are empty labels without actionable detail.

Suggestions

Add concrete, executable code examples for each pattern (e.g., modular SDK imports, security rules snippets, Firestore data modeling with actual collection/document structures).

Provide specific anti-pattern examples with code showing what NOT to do and the correct alternative, rather than just listing labels.

Create a workflow for common Firebase tasks (e.g., project setup, deploying security rules, using emulators) with explicit validation steps like 'firebase emulators:start' and 'firebase deploy --only firestore:rules'.

Remove the narrative backstory and replace with actionable content; if the skill is meant to be comprehensive, split into bundle files (e.g., SECURITY_RULES.md, DATA_MODELING.md) and reference them clearly from the main skill.

DimensionReasoningScore

Conciseness

The narrative framing ('You've seen the easy path...', 'The team that skipped security rules got pwned') is unnecessary padding that Claude doesn't need. The capabilities list is just a bullet list of Firebase service names Claude already knows. The content is noticeably verbose relative to the near-zero actionable information it provides.

2 / 5

Actionability

There is no concrete code, no executable commands, no specific examples, and no actual instructions. Every section is a vague label or abstract description (e.g., 'Import only what you need for smaller bundles') with zero implementation detail.

1 / 5

Workflow Clarity

There are no steps, no sequences, no validation checkpoints, and no workflows of any kind. The content is entirely declarative labels without any process guidance.

1 / 5

Progressive Disclosure

There is no bundle, no referenced files, and no structured navigation. The content is a shallow outline with no depth—sections like 'Patterns' and 'Anti-Patterns' are stubs with no links to detailed content or further reading.

1 / 5

Total

5

/

20

Passed

Description

11%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

This description reads as a persona/character prompt rather than a functional skill description. It uses first/second person voice ('You're a developer'), contains no concrete actions or capabilities, and completely lacks trigger guidance for when Claude should select this skill. It would be nearly useless for skill selection among multiple available skills.

Suggestions

Replace the persona framing with concrete actions in third person, e.g., 'Reviews Firebase project architecture for security vulnerabilities, cost optimization, and migration readiness.'

Add an explicit 'Use when...' clause with trigger terms like 'Firebase security rules', 'Firestore costs', 'Firebase migration', 'Cloud Functions', 'Firebase architecture review'.

List specific capabilities such as 'audits security rules, identifies cost pitfalls, recommends Firestore data modeling patterns, evaluates vendor lock-in risks' to distinguish this from generic Firebase help.

DimensionReasoningScore

Specificity

The description contains no concrete actions whatsoever. It uses vague, abstract language about experience ('shipped dozens of Firebase projects') and knowledge ('know its sharp edges') but never states what the skill actually does.

1 / 5

Completeness

The description fails to answer both 'what does this do' and 'when should Claude use it'. There is no 'Use when...' clause and no concrete description of capabilities. It reads as a persona statement rather than a skill description.

1 / 5

Trigger Term Quality

The term 'Firebase' appears multiple times, which is a relevant keyword, but there are no other natural trigger terms like 'Firestore', 'security rules', 'Cloud Functions', 'authentication', 'database', or specific actions users would request.

2 / 5

Distinctiveness Conflict Risk

While 'Firebase' provides some domain specificity, the description is so vague about what it actually does that it could conflict with any Firebase-related skill. It mentions security, costs, and migrations but doesn't commit to any specific niche.

2 / 5

Total

6

/

20

Passed

Validation

90%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation10 / 11 Passed

Validation for skill structure

CriteriaDescriptionResult

frontmatter_unknown_keys

Unknown frontmatter key(s) found; consider removing or moving to metadata

Warning

Total

10

/

11

Passed

Repository
administrakt0r/AI-Agents-Safe-Coding-Skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.