skills/celeroncoder/skills/agents-sdk/Gen Agent Trust Hub

agents-sdk

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides installation instructions for various Node.js packages related to the Cloudflare Agents ecosystem, including agents, @cloudflare/ai-chat, and @cloudflare/think. These are standard packages for the described development environment.
  • [DYNAMIC_EXECUTION]: Documentation for experimental features such as 'Codemode' and 'Browse the Web' describes mechanisms where an LLM generates and executes JavaScript. The skill notes that these actions occur within isolated Worker sandboxes or fresh browser sessions to ensure security.
  • [INDIRECT_PROMPT_INJECTION]: The skill identifies external data ingestion points like webhooks and email routing. It provides clear guidance on mitigating potential injection risks by using HMAC-SHA256 signature verification and incorporating human-in-the-loop approval steps.
  • [COMMAND_EXECUTION]: Instructions include the use of the Wrangler CLI for project management tasks, such as generating types and handling environment secrets securely.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:56 PM
Security Audit — agent-trust-hub — agents-sdk