Back to skill

Security audit

Cf Workers Logs

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it says by querying Cloudflare Workers logs, but it also tells the agent to search project .env files and print matching credential lines, which can expose API tokens.

Review this before installing. Use a narrowly scoped Cloudflare token, prefer exporting the two required variables directly, and do not let the agent recursively search .env files. Treat any token printed in a transcript as exposed and rotate it.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:85
Finding

Recursive Credential Search Exposes Cloudflare Secrets in Plaintext

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 85–88
Vulnerability Type: Plaintext sensitive-data exposure during credential discovery
Risk Level: Medium

Vulnerable Code

markdown
Read `CF_OBSERVABILITY_ACCOUNT_ID` and `CF_OBSERVABILITY_API_TOKEN` from environment variables. If not set in the shell, search for them in project `.env` files:

```bash
grep -r 'CF_OBSERVABILITY_' --include='.env' --include='.env.*' . 2>/dev/null
text

### Technical Analysis

When credentials are unavailable in the shell environment, the Skill instructs the agent to recursively search the current directory and print every matching line from `.env` and `.env.*` files. Because `grep` writes the complete matching lines to standard output, values such as `CF_OBSERVABILITY_API_TOKEN` are exposed in plaintext.

This output may be retained in the agent's context, command transcript, terminal scrollback, execution logs, or other telemetry. The recursive search also crosses nested directories, so it can discover credentials belonging to unrelated projects beneath the working directory.

Access to a credential is necessary to query Cloudflare, but recursively printing secret-bearing configuration is not necessary. The behavior therefore exceeds the minimum access needed for credential loading. The intended network request to the official `https://api.cloudflare.com` endpoint is consistent with the declared functionality; no evidence of transmission to an unrelated third party was found.

### Attack Path

1. A user invokes the Skill while the required Cloudflare variables are not exported in the shell.
2. The agent follows the fallback instruction and runs the recursive `grep` command from the project directory.
3. The command locates one or more `.env` files, potentially including files in nested or unrelated projects.
4. Complete matching assignments, including the Cloudflare bearer token, are printed to command output.
5. The exposed token is incorporated i
...[truncated 1026 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove the recursive command that prints secret-bearing lines.
  2. Require credentials to be supplied through the process environment or a secret manager whenever possible.
  3. If .env fallback is retained, load a single explicitly selected file without echoing its contents. Do not recursively search nested directories.
  4. Ask for user confirmation before reading a credential file that was not explicitly configured.
  5. Suppress and redact secret values in all command output, diagnostics, errors, and agent responses. Display only whether a variable was found.
  6. Avoid placing the bearer token directly in visible shell command text where execution tooling may log it. Use a protected configuration file, secure environment injection, or a secret-aware request mechanism.
  7. Recommend a dedicated token restricted to the intended Cloudflare account and the narrowest permission accepted by the API. Document the security implications if Cloudflare requires an Edit permission for query operations.
  8. Advise users to exclude .env files from version control, restrict their filesystem permissions, rotate any token exposed in prior transcripts, and review Cloudflare audit activity for unauthorized use.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Rogue AgentSelf-Modification, Session Persistence
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · README.md (reported line 47)May include surrounding context.

Option A: Project .env file (recommended, per-project isolation)

bash
# .env (make sure it's in .gitignore)
CF_OBSERVABILITY_ACCOUNT_ID=your-account-id
CF_OBSERVABILITY_API_TOKEN=your-api-token

Credential Access

High
Category
Privilege Escalation
Confidence
97% confidence
Finding

The instruction to grep project .env files for CF_OBSERVABILITY credentials is a concrete credential-access pattern. It authorizes broad scanning of local secret files, which may expose not only the intended token but additional sensitive material in the same files, making the skill materially more dangerous than a normal log-query helper.

Content

Scanner excerpt · SKILL.md (reported line 88)May include surrounding context.

Read CF_OBSERVABILITY_ACCOUNT_ID and CF_OBSERVABILITY_API_TOKEN from environment variables. If not set in the shell, search for them in project .env files:

bash
grep -r 'CF_OBSERVABILITY_' --include='.env' --include='.env.*' . 2>/dev/null

Step 2: Build and execute query

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · README.md (reported line 28)May include surrounding context.

md
2. Go to **Workers & Pages** in the sidebar
3. Find **Account ID** in the right-side **Account details** section — click to copy

### 2. Create an API Token

1. Go to **My Profile > API Tokens** in the Cloudflare dashboard
2. Click **Create Token**

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The skill instructs sending account-scoped query data to an external Cloudflare API without an explicit user-facing notice that logs and metadata will leave the local environment. Even though this is the intended integration, the absence of a network/privacy warning can surprise users and lead to unintended disclosure of operational data.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 26)May include surrounding context.

API Endpoint

text
POST https://api.cloudflare.com/client/v4/accounts/{accountId}/workers/observability/telemetry/query
Authorization: Bearer {apiToken}
Content-Type: application/json

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill directs the agent to access sensitive API credentials from environment variables and, if missing, to mine .env files, but provides no user-facing warning or consent boundary around secret handling. In an agent setting, that can normalize broad secret access and increase the chance of exposing or misusing credentials.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill expands its scope from querying logs to actively searching local project .env files for credentials. That behavior increases access to unrelated secrets stored in the workspace and creates an unnecessary secret-discovery capability beyond the minimum needed for the stated task.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

This markdown file explains how to configure an API token and use the skill to query Workers Observability logs, but it does not explicitly warn that invoking the skill sends query parameters and may retrieve potentially sensitive log contents from Cloudflare. For a skill that accesses remote observability data using credentials, a brief disclosure about privacy and data exposure would improve user awareness.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.