cloudflare-one
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external sources, such as Cloudflare account configurations, identity provider logs, and SCIM sync data. This creates a potential surface for indirect prompt injection if the ingested data contains malicious instructions.
- Ingestion points: The skill instructs the agent to gather context from account IDs, identity providers, SCIM/group sync data, and existing Cloudflare resources (Access apps, Gateway rules, etc.) as described in the "Workflow" and "Assessment Prompts" sections.
- Boundary markers: There are no explicit instructions to use delimiters or ignore embedded commands within the external data being processed.
- Capability inventory: The skill utilizes MCP tools to interact with the Cloudflare API, allowing for the inspection and potential modification of Cloudflare configurations.
- Sanitization: No explicit sanitization or validation mechanisms for external data are specified in the instructions.
- [SAFE]: The skill includes multiple references to official Cloudflare documentation and learning paths (e.g., developers.cloudflare.com). These resources originate from a well-known and trusted service provider.
Audit Metadata