cf-access-wall
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]: The setup scripts dynamically import a local helper library using a runtime-constructed path to the user's home directory. While this is an internal dependency, dynamic loading of executable code is a noteworthy pattern.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted configuration data from a JSON spec file.\n
- Ingestion points: Reads configuration from a spec file specified in the command-line arguments of setup-access.mjs.\n
- Boundary markers: Utilizes a JSON schema to enforce structure and validate input formats.\n
- Capability inventory: Performs network requests to Cloudflare's API, automates browser sessions on GitHub, and writes to a local secret vault.\n
- Sanitization: Employs regex validation for identifiers and uses a vault system to prevent secret exposure in logs or prompts.
Audit Metadata