cloudflare-security

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill retrieves and processes untrusted data from Cloudflare firewall events and audit logs, creating an attack surface for indirect prompt injection. Attackers could potentially embed malicious instructions within HTTP headers or other logged fields to influence the agent's behavior during log analysis.
  • Ingestion points: The tools get_firewall_events, list_audit_logs, list_security_events, and get_threat_score fetch data directly from external web traffic and account activity logs.
  • Boundary markers: The skill does not implement specific delimiters or instructions to treat log data as untrusted content, increasing the risk that the agent may follow instructions embedded within the logs.
  • Capability inventory: The skill provides read-only access to Cloudflare's security logs and does not include scripts with shell execution, file-writing, or outbound network exfiltration capabilities beyond its defined tools.
  • Sanitization: There is no evidence of content filtering, sanitization, or schema validation to strip potential injection vectors from the retrieved log data.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 04:29 PM
Security Audit — agent-trust-hub — cloudflare-security