cloudflare
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides detailed patterns for creating applications that ingest and process untrusted data from multiple sources including HTTP requests, emails, and message queues. It documents the use of powerful platform capabilities like network operations (
fetch), database access, and isolated code execution (Sandbox SDK). - Ingestion Points: Ingestion of external data via
fetchhandlers,Email Workers, andQueueconsumers is documented throughout the reference files (e.g.,references/email-routing/api.md,references/queues/api.md). - Boundary Markers: Code snippets demonstrate how to parse and handle data but do not enforce specific delimiter strategies, leaving those to the user's implementation.
- Capability Inventory: Documents extensive access to Cloudflare platform features including
fetch,D1SQL,KVstorage,Workers AI, and containerized command execution (Sandbox SDK). - Sanitization: The skill proactively provides guidance on security, such as emphasizing the requirement for prepared statements to prevent SQL injection in database operations (documented in
references/d1/api.md). - [EXTERNAL_DOWNLOADS]: The skill correctly references official Cloudflare SDKs and well-known developer tools. All dependencies listed are standard within the Cloudflare ecosystem and originate from trusted sources.
- [SAFE]: No malicious patterns, prompt injections, or unauthorized data exfiltration attempts were found. Code snippets use standard placeholders for configuration and credentials, and the overall posture of the skill is educational and helpful for Cloudflare development tasks.
Audit Metadata