Back to skill

Security audit

Wrangler

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward Cloudflare Wrangler command-reference skill, with powerful admin commands that users should run carefully.

Install this only if you want help operating Cloudflare with Wrangler. Before running delete, rollback, bulk, migration, SQL, or secret commands, verify the account, environment, resource names, and production impact; export or back up data where appropriate, and avoid putting plaintext secrets in shell history, logs, committed files, or shared terminals.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The skill documents high-risk Wrangler commands such as worker deletion, rollback, secret management, KV deletion, D1 deletion, and R2 object deletion without clear warnings, confirmation guidance, or advice to verify targets and environments first. In an agent setting, this increases the chance that a model or user will execute destructive or sensitive operations directly from the examples, causing unintended data loss, service disruption, or secret exposure.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.