cloudflare-r2

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill defines patterns for ingesting untrusted external data through file uploads. While this creates an attack surface for indirect prompt injection, the skill mitigates this by providing guidance on file type validation, unique filename generation, and secure access controls.
  • [CREDENTIALS_UNSAFE]: The templates demonstrate the use of R2 API keys and account IDs. The skill correctly identifies these as sensitive and instructs the user to use Wrangler secrets for secure storage rather than hardcoding them in the source code.
  • [COMMAND_EXECUTION]: Includes standard infrastructure management commands for the Cloudflare Wrangler CLI. These are necessary for the skill's primary function and target a trusted platform tool.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 12:00 AM
Security Audit — agent-trust-hub — cloudflare-r2