cloudflare-one-migrations
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest and map policies from external vendor exports (Zscaler ZIA/ZPA, Palo Alto) which are untrusted data sources that could contain embedded instructions to override agent behavior.
- Ingestion points: Section Workflow step 2 and Exports To Ask For detail the ingestion of external logs and policy exports.
- Boundary markers: The instructions lack requirements for delimiters or warnings to ignore instructions within the source data.
- Capability inventory: The skill assumes the agent has the capability to generate configurations and mapping plans based on the input.
- Sanitization: There are no instructions for sanitizing or validating the content of the requested configuration exports before processing.
Audit Metadata