skills/celeroncoder/skills/wrangler/Gen Agent Trust Hub

wrangler

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill provides extensive instructions for the agent to use the wrangler CLI to manage Cloudflare resources, including deploying code, managing databases, and configuring secrets.
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of the wrangler CLI and related development tools from Cloudflare's official npm registry.
  • [INDIRECT_PROMPT_INJECTION]: The skill creates an attack surface for indirect prompt injection by instructing the agent to process potentially untrusted data from external sources while having elevated capabilities.
  • Ingestion points: Commands such as wrangler tail (streaming live application logs) and wrangler kv key get (retrieving values from a KV store) ingest data that could be controlled by an external attacker.
  • Boundary markers: The instructions do not provide specific markers or guidance on how to distinguish external data from agent instructions.
  • Capability inventory: The agent environment has high-privilege capabilities, including the ability to deploy infrastructure (wrangler deploy), modify secrets (wrangler secret put), and initialize new projects (wrangler init).
  • Sanitization: There are no documented procedures for sanitizing or validating the data retrieved from external sources before it is processed by the agent.
  • [SAFE]: The skill incorporates strong security guidelines for secret management. It explicitly warns against hardcoding secrets in configuration files, passing them as command-line arguments, or piping them via insecure methods, favoring interactive prompts or secure environment variables.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:56 PM
Security Audit — agent-trust-hub — wrangler