cloudflare-email-service
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill documents patterns for ingesting untrusted email data into AI agents, creating a surface for potential indirect prompt injection attacks.
- Ingestion points: Raw email content is accessed via
message.rawinreferences/routing.mdandemail.getRaw()inreferences/sending.md. - Boundary markers: Code examples do not demonstrate the use of delimiters or instructions for the agent to ignore commands within the email body.
- Capability inventory: The skill enables capabilities such as sending emails (
env.EMAIL.send), forwarding messages (message.forward), and executing SQLite operations (storage.sql.exec). - Sanitization: Examples show direct use of email text and HTML fields without demonstrated sanitization or validation.
- [EXTERNAL_DOWNLOADS]: The skill incorporates official resources and standard developer packages.
- Fetches tools and documentation from Cloudflare's official GitHub repositories (
cloudflare/agents,cloudflare/mcp). - References and utilizes established npm packages for email tasks (
postal-mime,mimetext,wrangler) and type definitions (@cloudflare/workers-types).
Audit Metadata