agents-sdk
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill documents several interfaces that ingest untrusted data from external sources, creating a potential surface for indirect prompt injection attacks.
- Ingestion points: Data enters the agent's context through
onEmailinreferences/email.md(raw email parsing),onRequestfor webhooks inreferences/webhooks-push.md, and theAIChatAgentmessage lifecycle inreferences/streaming-chat.md. - Boundary markers: The provided code examples for handling email and webhooks do not demonstrate the use of explicit delimiters or instructions to ignore embedded commands before processing or responding to content.
- Capability inventory: Agents documented in this skill possess extensive capabilities, including executing SQL queries against local state, performing outbound network requests via
fetch, orchestrating durable background tasks viaAgentWorkflow, and executing arbitrary code using the Codemode tool. - Sanitization: Examples focus on technical parsing (e.g., using
PostalMimeorJSON.parse) but do not include patterns for sanitizing or filtering natural language instructions embedded within the processed data. - [DYNAMIC_EXECUTION]: The skill documents experimental features that enable the execution of code generated at runtime, typically by an LLM.
- Evidence:
references/codemode.mddescribes thecreateCodeToolandDynamicWorkerExecutor, which allow an agent to write and execute JavaScript in an isolated Worker sandbox. - Evidence:
references/browse-the-web.mddocuments thebrowser_executetool, which allows the execution of asynchronous JavaScript IIFEs within a browser session controlled via CDP. - Context: These patterns are presented as legitimate, experimental orchestration features within the Cloudflare Agents SDK environment.
Audit Metadata