cloudflare-worker-dev

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill guides the agent in building web request handlers, which naturally creates a surface for processing untrusted data from external HTTP requests.
  • Ingestion points: SKILL.md (fetch handlers designed to process Request objects).
  • Boundary markers: None specified in the code samples.
  • Capability inventory: The skill is configured with Bash, Read, Write, and Edit tools.
  • Sanitization: The guide proactively includes instructions for implementing security mitigations such as CORS header validation and IP-based rate limiting to protect the edge applications.
  • [EXTERNAL_DOWNLOADS]: The skill refers to official tooling and standard libraries required for the Cloudflare development lifecycle.
  • Evidence: References the wrangler CLI for deployment operations and the latlon-geohash library for implementing geographic caching logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 07:02 PM
Security Audit — agent-trust-hub — cloudflare-worker-dev