nextjs-on-cloudflare

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references and fetches additional agent skills and documentation from Cloudflare's official GitHub organization repositories.
  • [COMMAND_EXECUTION]: Provides instructions to execute npx skills add cloudflare/vinext, which downloads and installs project-specific tooling from the Cloudflare organization.
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to read and follow instructions from external markdown files (SKILL.md) hosted in the vinext repository. This represents a data ingestion surface where external content can influence agent behavior, though the source is the official repository for the framework.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 11:42 PM