cloudflare-email-service
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the automated processing of incoming emails, creating a surface for indirect prompt injection where an external sender could attempt to influence the agent's behavior through email content.
- Ingestion points: The
email()handler inreferences/routing.mdingests untrusted data via themessageobject, including headers, subject, and raw body content. - Boundary markers: The provided code examples do not include explicit boundary markers or instructions to the agent to ignore potentially malicious content within the email bodies.
- Capability inventory: The skill documentation describes capabilities including sending emails (
env.EMAIL.send), forwarding messages (message.forward), and storing content in Durable Object SQLite databases (ctx.storage.sql.exec) inreferences/routing.md. - Sanitization: No explicit sanitization or validation of the email content is present in the reference implementation snippets.
- [EXTERNAL_DOWNLOADS]: The skill fetches documentation, API specifications, and type definitions from Cloudflare's official domains and GitHub repositories (e.g.,
developers.cloudflare.com,github.com/cloudflare/mcp). These are well-known and official sources for the service being implemented. - [COMMAND_EXECUTION]: The documentation provides instructions for using the
wranglerCLI tool to manage email domain configurations, DNS records, and sending operations vianpx wrangler email.
Audit Metadata