cloudflare-one
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- Indirect Prompt Injection Surface: The skill is designed to retrieve and process information from external sources, including documentation and API schemas, to generate configurations and troubleshooting steps. While the sources specified are official vendor resources, the pattern of ingesting external content to inform administrative actions presents a standard interaction surface.
- Ingestion points: The skill retrieves data from official documentation sites, MCP servers, and API schemas (specified in
SKILL.md). - Boundary markers: There are no explicit instructions within the skill for the agent to use delimiters or ignore potentially conflicting instructions embedded within the retrieved documentation.
- Capability inventory: The skill allows the agent to propose architecture changes, create security policies, configure tunnels, and interact with the account API (specified in
SKILL.md). - Sanitization: The instructions do not explicitly detail sanitization or validation of the content retrieved from external sources before it is used to generate command proposals.
Audit Metadata