workers-best-practices
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to retrieve and process external documentation and local project files to inform code reviews and generation, creating a surface for indirect prompt injection.
- Ingestion points: External documentation from Cloudflare's official domain and local project files like Wrangler configuration and generated types.
- Boundary markers: The instructions lack explicit delimitation or warnings to treat retrieved documentation and project files as untrusted data.
- Capability inventory: The skill grants the agent the ability to write, review, and configure Workers code based on the ingested information.
- Sanitization: There are no instructions for sanitizing or validating the content of retrieved documentation or project files before processing.
Audit Metadata