cloudflare-os-operator
Pass
Audited by Gen Agent Trust Hub on Aug 22, 2026
Risk Level: SAFE
Full Analysis
- Robust Security Guardrails: The skill incorporates multiple 'Hard Stops' and explicit rules to prevent the leakage of secrets, credentials, or sensitive logs during operation and troubleshooting.
- Controlled Infrastructure Mutation: Critical changes to DNS, Cloudflare Access, and Worker identities require explicit operator approval and a documented mutation summary, adhering to the principle of least privilege.
- Official Tooling and Best Practices: It leverages project-pinned versions of
wranglerandpnpm, following standard deployment workflows for the Cloudflare platform. - Trust Boundary Management: The instructions emphasize verifying and maintaining authentication boundaries (Cloudflare Access) and data isolation (sharing domains) throughout the deployment lifecycle.
- Sanitized Evidence Collection: Troubleshooting procedures are designed to collect only the minimum necessary sanitized evidence, specifically prohibiting the capture of authentication tokens or private request/response bodies.
Audit Metadata