sandbox-sdk
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines a surface area for processing untrusted data (code and shell commands) which could lead to indirect prompt injection if an attacker-controlled input is passed to the execution methods.
- Ingestion points: Untrusted data enters the agent context via the
codeparameter inrunCode()and thecommandparameter inexec()as described inSKILL.mdandreferences/api-quick-ref.md. - Boundary markers: None are present in the provided implementation examples to delimit user input from system instructions.
- Capability inventory: The sandbox environment provides capabilities for shell command execution (
exec), filesystem access (writeFile,readFile,mkdir), and network exposure (exposePort) as detailed inreferences/api-quick-ref.md. - Sanitization: No explicit sanitization or input validation is demonstrated in the skill instructions; the architecture relies on the underlying sandbox isolation to mitigate impact.
- [DYNAMIC_EXECUTION]: The skill's primary purpose is to facilitate the dynamic execution of code (Python, JavaScript, TypeScript) using the
runCodemethod and the creation of code contexts for state persistence. - [COMMAND_EXECUTION]: The skill enables the execution of arbitrary shell commands within the sandbox environment using the
sandbox.exec()method. - [EXTERNAL_DOWNLOADS]: The skill references and installs dependencies from Cloudflare's official resources.
- Fetches the
@cloudflare/sandboxpackage from the official registry. - Utilizes the
docker.io/cloudflare/sandbox:0.7.0base image for containerized execution. - References official documentation and example code from
developers.cloudflare.comand Cloudflare's GitHub repositories.
Audit Metadata