Back to skill

Security audit

Cloudflare Mcp

Security checks across malware telemetry and agentic risk

Overview

This appears to be a legitimate Cloudflare integration, but it gives an agent broad OAuth-backed ability to change live Cloudflare resources without clear confirmation or scope limits.

Install only if you intentionally want an agent to manage Cloudflare resources. Use the narrowest OAuth permissions available, prefer a test account or limited zone, require explicit confirmation before DNS, Workers, storage, or account changes, and revoke the Cloudflare OAuth grant when finished.

Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
89% confidence
Finding
The trigger phrases are very broad and include common terms like "DNS", "Workers", and "CF", which can match ordinary discussion and invoke the skill in contexts where the user did not clearly intend Cloudflare API actions. In this skill, that risk is amplified because the skill supports authenticated API operations, including resource creation, so accidental invocation can lead to unintended access or modifications.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill states that in Code Mode the model will automatically search API endpoints and execute calls, while also advertising write-capable actions like creating DNS records, KV namespaces, and R2 buckets. Without a prominent warning and explicit confirmation boundary for state-changing operations, users may trigger real Cloudflare changes unintentionally after OAuth authorization.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.