agents-sdk

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill documents several interfaces that ingest untrusted data from external sources, creating a potential surface for indirect prompt injection attacks.
  • Ingestion points: Data enters the agent's context through onEmail in references/email.md (raw email parsing), onRequest for webhooks in references/webhooks-push.md, and the AIChatAgent message lifecycle in references/streaming-chat.md.
  • Boundary markers: The provided code examples for handling email and webhooks do not demonstrate the use of explicit delimiters or instructions to ignore embedded commands before processing or responding to content.
  • Capability inventory: Agents documented in this skill possess extensive capabilities, including executing SQL queries against local state, performing outbound network requests via fetch, orchestrating durable background tasks via AgentWorkflow, and executing arbitrary code using the Codemode tool.
  • Sanitization: Examples focus on technical parsing (e.g., using PostalMime or JSON.parse) but do not include patterns for sanitizing or filtering natural language instructions embedded within the processed data.
  • [DYNAMIC_EXECUTION]: The skill documents experimental features that enable the execution of code generated at runtime, typically by an LLM.
  • Evidence: references/codemode.md describes the createCodeTool and DynamicWorkerExecutor, which allow an agent to write and execute JavaScript in an isolated Worker sandbox.
  • Evidence: references/browse-the-web.md documents the browser_execute tool, which allows the execution of asynchronous JavaScript IIFEs within a browser session controlled via CDP.
  • Context: These patterns are presented as legitimate, experimental orchestration features within the Cloudflare Agents SDK environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 11:41 PM