cloudflare
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: Provides instructions for standard developer operations using the Wrangler CLI, such as
wrangler deployfor deployment andwrangler devfor local simulation. These are legitimate tools for managing Cloudflare resources. - [EXTERNAL_DOWNLOADS]: Mentions the installation of official developer tools including
wranglerand@cloudflare/next-on-pages. These originate from a well-known service and are standard dependencies for the platform. - [CREDENTIALS_UNSAFE]: Explicitly includes a security advisory in the 'Common Mistakes' section, warning users not to store secrets in configuration files and instead use the
wrangler secret putcommand for encrypted storage. - [INDIRECT_PROMPT_INJECTION]: The skill provides code patterns for handling incoming HTTP request data. While this creates an attack surface for applications built using these patterns, the documentation mitigates risk by instructing the use of prepared statements and parameterized queries (
.bind()) to prevent injection attacks in D1 databases.
Audit Metadata