sandbox-sdk
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of the
@cloudflare/sandboxpackage via NPM and utilizes official Docker images from Docker Hub (docker.io/cloudflare/sandbox). It also retrieves documentation and code examples from Cloudflare's official domains and GitHub repositories. All external resources are from well-known services or trusted organizations. - [COMMAND_EXECUTION]: The skill provides methods such as
sandbox.exec()to run shell commands within the isolated container environment. This is the intended functionality of the sandbox SDK for building CI/CD systems or interactive dev environments. - [DYNAMIC_EXECUTION]: The skill includes the
sandbox.runCode()method, which allows for the runtime interpretation of Python, JavaScript, and TypeScript. This is designed for executing LLM-generated code within a secure, isolated context. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to process and execute untrusted or LLM-generated code, creating a potential surface for indirect prompt injection.
- Ingestion points: Untrusted code or command strings are passed to the
runCodeandexecmethods as shown inSKILL.mdandreferences/api-quick-ref.md. - Boundary markers: The SDK itself serves as the isolation boundary, keeping execution limited to the containerized environment.
- Capability inventory: The skill allows for file system operations (
readFile,writeFile), network port exposure (exposePort), and arbitrary command execution (exec) within the sandbox. - Sanitization: The skill relies on the underlying Cloudflare Workers infrastructure to provide secure isolation for the executed code.
Audit Metadata