T08 · Insecure Dependencies
- Location
SKILL.md:27- Finding
Unpinned npm Packages Are Installed or Executed
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is a coherent Cloudflare email integration guide, but users should review real-send examples, logging, and unpinned tooling before use.
Install/use this skill only for Cloudflare Email Service work. Before sending, confirm the exact recipients, sender, content, and attachments; avoid sending secrets or personal data unless authorized. Pin Wrangler and npm dependency versions, use least-privilege Cloudflare tokens, avoid full email-body logging, and escape or sanitize any text inserted into HTML email.
SKILL.md:27Unpinned npm Packages Are Installed or Executed
references/routing.md:104Inbound Email Body Is Written to Application Logs
references/routing.md:179Untrusted Reply Content Is Embedded in HTML Without Escaping
``` ### Impact Assessment The vulnerability does not directly grant server or Cloudflare account privileges. Its primary scope is the content and trust context of emails sent by the legitimate domain. Potential impact includes: ...[truncated 496 chars]
The manifest description is extremely broad and includes generic phrases like use for coding agents, any app, and even simple requests, which increases the chance the skill is invoked for loosely related prompts. Over-broad activation can cause an agent to inappropriately prioritize this skill's instructions and email-sending workflows in contexts where external communication or sensitive-data handling was not clearly requested.
The skill gives actionable instructions for sending email, including code and API endpoints, but does not warn about privacy implications, recipient consent, data disclosure, or the fact that content will be transmitted to external recipients and Cloudflare services. In an agent setting, this omission can normalize outbound messaging and increase the risk of sending sensitive or unintended data without adequate user confirmation.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Or via REST API:
curl "https://api.cloudflare.com/client/v4/accounts/${CLOUDFLARE_ACCOUNT_ID}/email/sending/send" \
--header "Authorization: Bearer ${CLOUDFLARE_API_TOKEN}" \
--header "Content-Type: application/json" \
--data '{
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Manually suppress an address:
curl -X POST "https://api.cloudflare.com/client/v4/accounts/{account_id}/email/sending/suppression" \
--header "Authorization: Bearer <API_TOKEN>" \
--header "Content-Type: application/json" \
--data '{ "email": "user@example.com", "expires_at": "2026-06-01T00:00:00Z" }'
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
Note: emailSendingAdaptive filters use datetime_geq/datetime_leq (Time type, e.g. "2026-04-01T00:00:00Z"), while emailSendingAdaptiveGroups uses date_geq/date_leq (Date type, e.g. "2026-04-01").
curl example:
curl "https://api.cloudflare.com/client/v4/graphql" \
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
POST https://api.cloudflare.com/client/v4/accounts/{account_id}/email/sending/send
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
POST https://api.cloudflare.com/client/v4/accounts/{account_id}/email/sending/send
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
POST https://api.cloudflare.com/client/v4/accounts/{account_id}/email/sending/send
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
POST https://api.cloudflare.com/client/v4/accounts/{account_id}/email/sending/send
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
POST https://api.cloudflare.com/client/v4/accounts/{account_id}/email/sending/send
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
POST https://api.cloudflare.com/client/v4/accounts/{account_id}/email/sending/send
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
POST https://api.cloudflare.com/client/v4/accounts/{account_id}/email/sending/send
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
POST https://api.cloudflare.com/client/v4/accounts/{account_id}/email/sending/send
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
POST https://api.cloudflare.com/client/v4/accounts/{account_id}/email/sending/send
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
POST https://api.cloudflare.com/client/v4/accounts/{account_id}/email/sending/send
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
POST https://api.cloudflare.com/client/v4/accounts/{account_id}/email/sending/send
No suspicious patterns detected.