Back to skill

Security audit

Wrangler

Security checks for vulnerabilities and agentic risk

Overview

This is a straightforward Cloudflare Wrangler command reference, but users should be careful because several commands can change or delete live cloud resources.

Install this only if you intend your agent to help with Cloudflare administration. Prefer a pinned, project-local Wrangler dependency, verify the active Cloudflare account and environment before running commands, back up important D1/R2/KV data before destructive operations, and handle secret files as sensitive material.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:11
Finding

Unpinned Wrangler Package Installation and Execution

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, line 11
Vulnerability Type: Unpinned third-party dependency execution
Risk Level: Medium

Vulnerable Code Snippet:

markdown
- Install: `npm install -g wrangler` or use project-local `npx wrangler`

Technical Analysis

The documented commands install or execute wrangler without specifying a reviewed version. npm install -g wrangler resolves the package version from the configured npm registry and installs it globally. Depending on the local environment, npx wrangler may download and execute a package that is not already installed.

Consequently, the code executed by these commands can change after this skill has been reviewed. If the upstream package, an npm account, the configured package registry, or the dependency chain is compromised, following the instructions could execute attacker-controlled package code under the invoking user's account. npm lifecycle scripts and the CLI itself may run during installation or invocation.

This is a supply-chain weakness rather than evidence that the current Wrangler package is malicious.

Attack Path

  1. An attacker compromises the Wrangler package distribution channel, one of its dependencies, an authorized publisher account, or a registry used by the victim.
  2. The attacker publishes or serves a malicious package release that satisfies the unpinned package request.
  3. A user follows the skill instructions and runs npm install -g wrangler or invokes npx wrangler without a verified local installation.
  4. npm retrieves the attacker-controlled release or dependency.
  5. Malicious lifecycle or CLI code executes with the permissions of the user running the command.
  6. The payload can access resources available to that user, potentially including local project files, environment variables, npm configuration, cached credentials, and authenticated Cloudflare deployment capabilities.

Impact Assess

...[truncated 763 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin Wrangler to a reviewed, explicit version rather than resolving the latest available release:

    bash
    npm install --save-dev --save-exact wrangler@<reviewed-version>
    
  2. Commit package.json and the generated lockfile, review lockfile changes, and use deterministic installation in automated environments:

    bash
    npm ci
    
  3. Execute only the verified project-local installation. Avoid implicit npx downloads:

    bash
    npx --no-install wrangler
    

    Alternatively, invoke the local binary directly:

    bash
    ./node_modules/.bin/wrangler
    
  4. Configure an approved npm registry and retain package-integrity metadata in the lockfile. Use registry access controls and dependency-scanning tools to detect compromised or unexpected releases.

  5. Review package provenance, publisher changes, lifecycle scripts, and dependency updates before upgrading the pinned version.

  6. Run Wrangler using a least-privileged operating-system account and narrowly scoped Cloudflare credentials. Avoid exposing unrelated secrets in the execution environment.

  7. Update SKILL.md so that its prerequisite instructions identify the approved version and explicitly warn users not to permit npx to download an unreviewed package.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (8)

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · SKILL.md (reported line 63)May include surrounding context.

wrangler secret delete

Bulk upload from JSON file

wrangler secret bulk secrets.json

text

### KV (Key-Value Store)

Missing User Warnings

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

The D1 section includes arbitrary SQL execution and database deletion commands without warning about production impact, destructive queries, or irreversible data loss. In this skill's context, these commands operate on live cloud databases, so omissions materially increase the risk of accidental corruption, exfiltration, or deletion.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The skill recommends using npx wrangler without pinning a specific package version, which can fetch and execute whatever version is current at runtime. In an agent setting, this increases supply-chain risk and can lead to unexpected behavior or execution of a compromised upstream release.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill presents destructive operations such as rollback and delete without cautionary guidance, confirmation steps, or advice to verify the target environment. In an agent-assisted workflow, this increases the chance of accidental service disruption or deletion of production resources.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The secret-management section omits warnings about handling sensitive values, especially piping plaintext via shell or bulk-loading from files that may be committed, logged, or exposed on disk. In a credential-management context, poor guidance can directly lead to secret leakage or unintended rotation of live credentials.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The R2 and Queue sections document deletion commands without highlighting irreversibility or prompting users to validate the target bucket, object, or queue. In cloud infrastructure workflows, such omissions can lead to preventable data loss or operational outages.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The manifest description at L003 scopes the skill to Workers, KV, D1, R2, secrets management, and tailing logs. However, the documented capabilities in the skill body add wrangler queues create/list/delete, which is a separate Cloudflare resource not mentioned in the manifest description.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
76% confidence
Finding

This skill is framed throughout as a Wrangler CLI skill, and the note says 'Wrangler doesn't directly manage custom domains.' In the same statement, it instructs users to use the Cloudflare API, which introduces an alternate capability path outside the claimed Wrangler-only mechanism and creates intent ambiguity in the documentation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.