cf-proxy

Warn

Audited by Gen Agent Trust Hub on Oct 8, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCREDENTIALS_UNSAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill is designed to fetch source code from an external GitHub repository (cmliu/edgetunnel) that is not maintained by the skill author or a trusted vendor.
  • [REMOTE_CODE_EXECUTION]: The workflow automates the deployment and execution of this externally sourced code within the user's Cloudflare Pages environment, which constitutes remote code execution in a cloud context.
  • [CREDENTIALS_UNSAFE]: To perform its tasks, the skill workflow requires the collection and use of sensitive Cloudflare account credentials (API tokens or keys) and potentially third-party DNS provider credentials (DNSExit).
Audit Metadata
Risk Level
MEDIUM
Analyzed
Oct 8, 2026, 09:46 PM