sandbox-sdk

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a surface area for processing untrusted data (code and shell commands) which could lead to indirect prompt injection if an attacker-controlled input is passed to the execution methods.
  • Ingestion points: Untrusted data enters the agent context via the code parameter in runCode() and the command parameter in exec() as described in SKILL.md and references/api-quick-ref.md.
  • Boundary markers: None are present in the provided implementation examples to delimit user input from system instructions.
  • Capability inventory: The sandbox environment provides capabilities for shell command execution (exec), filesystem access (writeFile, readFile, mkdir), and network exposure (exposePort) as detailed in references/api-quick-ref.md.
  • Sanitization: No explicit sanitization or input validation is demonstrated in the skill instructions; the architecture relies on the underlying sandbox isolation to mitigate impact.
  • [DYNAMIC_EXECUTION]: The skill's primary purpose is to facilitate the dynamic execution of code (Python, JavaScript, TypeScript) using the runCode method and the creation of code contexts for state persistence.
  • [COMMAND_EXECUTION]: The skill enables the execution of arbitrary shell commands within the sandbox environment using the sandbox.exec() method.
  • [EXTERNAL_DOWNLOADS]: The skill references and installs dependencies from Cloudflare's official resources.
  • Fetches the @cloudflare/sandbox package from the official registry.
  • Utilizes the docker.io/cloudflare/sandbox:0.7.0 base image for containerized execution.
  • References official documentation and example code from developers.cloudflare.com and Cloudflare's GitHub repositories.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:56 PM
Security Audit — agent-trust-hub — sandbox-sdk