cloudflare-tunnel-publish
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill downloads the cloudflared binary from the official Cloudflare GitHub repository during installation.
- Evidence: scripts/run_tunnel.sh fetches the binary from https://github.com/cloudflare/cloudflared/releases/latest/download/cloudflared-linux-${suffix}.
- Context: This is a standard functional requirement for the skill, and the source is a trusted organization.
- [DYNAMIC_EXECUTION]: The keepalive script executes a command stored in a local state file to restart the application if it crashes.
- Evidence: scripts/keepalive.sh uses setsid bash -c 'exec $APP_CMD' to revive the target service.
- Context: The command is provided by the agent/user during the initial setup phase and is necessary for the self-healing functionality.
- [COMMAND_EXECUTION]: The skill utilizes various shell commands to manage background processes and monitor service health.
- Evidence: scripts/keepalive.sh and scripts/run_tunnel.sh manage process IDs and use curl for reachability checks.
- [REMOTE_CODE_EXECUTION]: Automated scanner flags regarding piped execution to python3 were evaluated and found to be safe.
- Evidence: SKILL.md contains instructions to use curl ... | python3 -m json.tool for DNS diagnostics.
- Context: The pipe is used solely to invoke the standard library's JSON formatter for human-readable output, which is not an execution of untrusted remote code.
Audit Metadata