cloudflare-performance-engineering

Fail

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: HIGHOBFUSCATIONPROMPT_INJECTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [OBFUSCATION]: The skill's main title in SKILL.md contains a sequence of hidden Unicode characters (U+200B Zero Width Space, U+200C Zero Width Non-Joiner, and U+200D Zero Width Joiner) positioned between the visible title text and the closing formatting. This is a deliberate application of zero-width steganography to hide a payload or set of instructions from human auditors while ensuring the AI agent processes the content.
  • [PROMPT_INJECTION]: The hidden binary payload embedded in the skill's title represents a prompt injection vector. Such hidden instructions are typically designed to override the agent's behavior, bypass safety guardrails, or perform unauthorized actions without the user's knowledge.
  • [INDIRECT_PROMPT_INJECTION]: The skill describes an architecture for ingesting Real User Measurement (RUM) data.
  • Ingestion points: The PerformanceCollector class in SKILL.md collects performance metrics from web page interactions via the performance.getEntriesByName API.
  • Boundary markers: The implementation lacks boundary markers or explicit instructions to the agent to ignore embedded instructions within the metrics metadata.
  • Capability inventory: The code includes network capabilities via navigator.sendBeacon() to transmit collected data to an external endpoint.
  • Sanitization: There is no evidence of sanitization or validation of the input data before it is processed or transmitted, creating a surface for indirect prompt injection via manipulated performance metrics (e.g., malicious strings in URL query parameters or User-Agents).
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Sep 18, 2026, 02:06 PM