cloudflare-deployment
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the official
wranglerCLI to perform infrastructure operations, including authentication (wrangler login), resource provisioning, and secret management (wrangler secret put). These are standard operational procedures for the target platform. - [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow that involves ingesting data from external services, which introduces a theoretical surface for indirect prompt injection.
- Ingestion points: External data enters the agent context via
env.MY_KV.get,env.MY_BUCKET.get, andenv.DBdatabase queries as shown inSKILL.md. - Boundary markers: The skill does not define specific boundary markers for separating external data from agent instructions during prompt interpolation.
- Capability inventory: The skill can perform file system operations (via CLI), database queries, and storage reads/writes, and it can interact with external APIs.
- Sanitization: The skill mitigates risks by instructing the use of
zodandsafeJsonParsefrom the@autumnsgrove/latticelibrary to validate and sanitize data at the application boundary.
Audit Metadata