software-cloudflare-wrangler
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references and downloads the Wrangler CLI from the npm registry. It also directs the agent to fetch up-to-date documentation and configuration schemas from official Cloudflare domains (developers.cloudflare.com) and local project directories.
- [COMMAND_EXECUTION]: The core function of the skill is to provide a comprehensive reference for executing wrangler CLI commands. These commands manage a wide range of Cloudflare services, including deployments, storage (KV, R2, D1), and platform features (AI, Containers, Workflows). Additionally, it uses a local utility script agents-skills-feedback-loop/scripts/append_learning.py to maintain a learnings log.
- [INDIRECT_PROMPT_INJECTION]: The skill instructions establish a workflow where the agent ingests external data from Cloudflare's documentation and local node_modules schemas to inform its actions. While this is necessary for maintaining technical accuracy, it introduces a surface where malformed documentation or schemas could influence agent behavior.
- Ingestion points: node_modules/wrangler/config-schema.json, https://developers.cloudflare.com/workers/wrangler/.
- Boundary markers: None explicitly defined for these retrieval steps.
- Capability inventory: Full Wrangler CLI suite, including code deployment, secret management, and data access across all Cloudflare storage primitives.
- Sanitization: No specific sanitization or validation of the retrieved documentation content is mentioned.
Audit Metadata