wrangler
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill provides extensive instructions for the agent to use the
wranglerCLI to manage Cloudflare resources, including deploying code, managing databases, and configuring secrets. - [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of the
wranglerCLI and related development tools from Cloudflare's official npm registry. - [INDIRECT_PROMPT_INJECTION]: The skill creates an attack surface for indirect prompt injection by instructing the agent to process potentially untrusted data from external sources while having elevated capabilities.
- Ingestion points: Commands such as
wrangler tail(streaming live application logs) andwrangler kv key get(retrieving values from a KV store) ingest data that could be controlled by an external attacker. - Boundary markers: The instructions do not provide specific markers or guidance on how to distinguish external data from agent instructions.
- Capability inventory: The agent environment has high-privilege capabilities, including the ability to deploy infrastructure (
wrangler deploy), modify secrets (wrangler secret put), and initialize new projects (wrangler init). - Sanitization: There are no documented procedures for sanitizing or validating the data retrieved from external sources before it is processed by the agent.
- [SAFE]: The skill incorporates strong security guidelines for secret management. It explicitly warns against hardcoding secrets in configuration files, passing them as command-line arguments, or piping them via insecure methods, favoring interactive prompts or secure environment variables.
Audit Metadata