cloudflare-worker-dev
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill guides the agent in building web request handlers, which naturally creates a surface for processing untrusted data from external HTTP requests.
- Ingestion points:
SKILL.md(fetch handlers designed to processRequestobjects). - Boundary markers: None specified in the code samples.
- Capability inventory: The skill is configured with
Bash,Read,Write, andEdittools. - Sanitization: The guide proactively includes instructions for implementing security mitigations such as CORS header validation and IP-based rate limiting to protect the edge applications.
- [EXTERNAL_DOWNLOADS]: The skill refers to official tooling and standard libraries required for the Cloudflare development lifecycle.
- Evidence: References the
wranglerCLI for deployment operations and thelatlon-geohashlibrary for implementing geographic caching logic.
Audit Metadata