skills/midudev/autoskills/agents-sdk/Gen Agent Trust Hub

agents-sdk

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill documents 'Codemode', an experimental feature that allows an LLM to generate and execute JavaScript within an isolated Worker sandbox using the DynamicWorkerExecutor. This involves the runtime assembly and execution of model-generated code.
  • [DYNAMIC_EXECUTION]: Documentation for 'Browser Tools' describes the browser_execute tool, which allows the LLM to write and run asynchronous JavaScript IIFEs within a fresh browser session for web scraping and interaction.
  • [INDIRECT_PROMPT_INJECTION]: The skill outlines patterns for handling untrusted external data, which creates a vulnerability surface for indirect prompt injection.
  • Ingestion points: External data enters the agent via the onEmail handler (references/email.md), webhook processing in onRequest (references/webhooks-push.md), and content retrieved via browser_search (references/browse-the-web.md).
  • Boundary markers: The provided code examples lack explicit delimiters or instructions to the model to ignore potential instructions embedded within these external data sources.
  • Capability inventory: The agent environment possesses significant capabilities, including persistent state modification, SQL query execution, email response generation, and the aforementioned dynamic code execution environments.
  • Sanitization: The instructional snippets do not demonstrate sanitization or validation of external payloads before they are processed by the agent logic.
  • [EXTERNAL_DOWNLOADS]: The skill instructs the user to install several packages from public registries, including @cloudflare/ai-chat, @cloudflare/codemode, and web-push. These are recognized as legitimate dependencies for the Cloudflare ecosystem.
  • [COMMAND_EXECUTION]: The skill includes instructions for running standard development commands such as npm install and npx wrangler types to set up the environment and generate bindings.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 11:19 PM
Security Audit — agent-trust-hub — agents-sdk