cloudflare-one

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external sources, such as Cloudflare account configurations, identity provider logs, and SCIM sync data. This creates a potential surface for indirect prompt injection if the ingested data contains malicious instructions.
  • Ingestion points: The skill instructs the agent to gather context from account IDs, identity providers, SCIM/group sync data, and existing Cloudflare resources (Access apps, Gateway rules, etc.) as described in the "Workflow" and "Assessment Prompts" sections.
  • Boundary markers: There are no explicit instructions to use delimiters or ignore embedded commands within the external data being processed.
  • Capability inventory: The skill utilizes MCP tools to interact with the Cloudflare API, allowing for the inspection and potential modification of Cloudflare configurations.
  • Sanitization: No explicit sanitization or validation mechanisms for external data are specified in the instructions.
  • [SAFE]: The skill includes multiple references to official Cloudflare documentation and learning paths (e.g., developers.cloudflare.com). These resources originate from a well-known and trusted service provider.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:56 PM
Security Audit — agent-trust-hub — cloudflare-one