cloudflare-tunnel-publish

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill downloads the cloudflared binary from the official Cloudflare GitHub repository during installation.
  • Evidence: scripts/run_tunnel.sh fetches the binary from https://github.com/cloudflare/cloudflared/releases/latest/download/cloudflared-linux-${suffix}.
  • Context: This is a standard functional requirement for the skill, and the source is a trusted organization.
  • [DYNAMIC_EXECUTION]: The keepalive script executes a command stored in a local state file to restart the application if it crashes.
  • Evidence: scripts/keepalive.sh uses setsid bash -c 'exec $APP_CMD' to revive the target service.
  • Context: The command is provided by the agent/user during the initial setup phase and is necessary for the self-healing functionality.
  • [COMMAND_EXECUTION]: The skill utilizes various shell commands to manage background processes and monitor service health.
  • Evidence: scripts/keepalive.sh and scripts/run_tunnel.sh manage process IDs and use curl for reachability checks.
  • [REMOTE_CODE_EXECUTION]: Automated scanner flags regarding piped execution to python3 were evaluated and found to be safe.
  • Evidence: SKILL.md contains instructions to use curl ... | python3 -m json.tool for DNS diagnostics.
  • Context: The pipe is used solely to invoke the standard library's JSON formatter for human-readable output, which is not an execution of untrusted remote code.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 04:28 AM
Security Audit — agent-trust-hub — cloudflare-tunnel-publish