cloudflare-deployment

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the official wrangler CLI to perform infrastructure operations, including authentication (wrangler login), resource provisioning, and secret management (wrangler secret put). These are standard operational procedures for the target platform.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow that involves ingesting data from external services, which introduces a theoretical surface for indirect prompt injection.
  • Ingestion points: External data enters the agent context via env.MY_KV.get, env.MY_BUCKET.get, and env.DB database queries as shown in SKILL.md.
  • Boundary markers: The skill does not define specific boundary markers for separating external data from agent instructions during prompt interpolation.
  • Capability inventory: The skill can perform file system operations (via CLI), database queries, and storage reads/writes, and it can interact with external APIs.
  • Sanitization: The skill mitigates risks by instructing the use of zod and safeJsonParse from the @autumnsgrove/lattice library to validate and sanitize data at the application boundary.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 04:09 PM
Security Audit — agent-trust-hub — cloudflare-deployment