cloudflare-email-service

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the automated processing of incoming emails, creating a surface for indirect prompt injection where an external sender could attempt to influence the agent's behavior through email content.
  • Ingestion points: The email() handler in references/routing.md ingests untrusted data via the message object, including headers, subject, and raw body content.
  • Boundary markers: The provided code examples do not include explicit boundary markers or instructions to the agent to ignore potentially malicious content within the email bodies.
  • Capability inventory: The skill documentation describes capabilities including sending emails (env.EMAIL.send), forwarding messages (message.forward), and storing content in Durable Object SQLite databases (ctx.storage.sql.exec) in references/routing.md.
  • Sanitization: No explicit sanitization or validation of the email content is present in the reference implementation snippets.
  • [EXTERNAL_DOWNLOADS]: The skill fetches documentation, API specifications, and type definitions from Cloudflare's official domains and GitHub repositories (e.g., developers.cloudflare.com, github.com/cloudflare/mcp). These are well-known and official sources for the service being implemented.
  • [COMMAND_EXECUTION]: The documentation provides instructions for using the wrangler CLI tool to manage email domain configurations, DNS records, and sending operations via npx wrangler email.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 11:41 PM