wrangler

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses the wrangler command-line interface to perform management tasks on Cloudflare services, including deploying workers, managing KV namespaces, interacting with R2 buckets, and executing SQL queries on D1 databases.
  • [INDIRECT_PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests data from external, potentially untrusted sources and has significant capabilities.
  • Ingestion points: The skill reads external data via wrangler kv key get, wrangler r2 object list, and wrangler d1 execute (SKILL.md).
  • Boundary markers: There are no specific delimiters or instructions to ignore embedded commands when processing the output of these retrieval operations.
  • Capability inventory: The skill can execute various CLI commands that modify cloud infrastructure, manage secrets, and perform network-based deployments across all mentioned scripts.
  • Sanitization: No sanitization, validation, or escaping of the content retrieved from KV, R2, or D1 is implemented before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 10:18 AM
Security Audit — agent-trust-hub — wrangler