Back to skill

Security audit

Cloudflare Email Service

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Cloudflare email integration guide, but users should review real-send examples, logging, and unpinned tooling before use.

Install/use this skill only for Cloudflare Email Service work. Before sending, confirm the exact recipients, sender, content, and attachments; avoid sending secrets or personal data unless authorized. Pin Wrangler and npm dependency versions, use least-privilege Cloudflare tokens, avoid full email-body logging, and escape or sanitize any text inserted into HTML email.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:27
Finding

Unpinned npm Packages Are Installed or Executed

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/routing.md:104
Finding

Inbound Email Body Is Written to Application Logs

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
references/routing.md:179
Finding

Untrusted Reply Content Is Embedded in HTML Without Escaping

Content
View full analysis
${replyBody}`, ``` ### Technical Analysis The example interpolates `replyBody` directly into an HTML email body without HTML escaping or sanitization. The surrounding workflow states that a user or agent can decide what reply to send. Therefore, the value may originate from user input, inbound email content, or AI-generated output and should not automatically be considered trusted HTML. An attacker-controlled value can terminate the intended paragraph and insert arbitrary email markup, deceptive links, remote tracking resources, or misleading visual content. JavaScript execution is generally restricted by email clients, but HTML injection remains security-relevant because email clients commonly render links, images, formatting, and other markup. ### Attack Path 1. An attacker supplies crafted content through an inbound email, stored message, compromised account, or prompt-manipulated AI draft. 2. The crafted content reaches `replyToStoredEmail` as `replyBody`. 3. The application interpolates it directly into the HTML template. 4. The outbound email contains attacker-controlled HTML rather than a safely encoded text representation. 5. The recipient's email client renders deceptive markup, external resources, or phishing links. 6. The recipient may disclose credentials, visit an attacker-controlled site, or unknowingly trigger remote tracking. An example malicious value could close the paragraph and insert a deceptive link: ```html

Review the secure message

``` ### Impact Assessment The vulnerability does not directly grant server or Cloudflare account privileges. Its primary scope is the content and trust context of emails sent by the legitimate domain. Potential impact includes: ...[truncated 496 chars]

Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (29)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest description is extremely broad and includes generic phrases like use for coding agents, any app, and even simple requests, which increases the chance the skill is invoked for loosely related prompts. Over-broad activation can cause an agent to inappropriately prioritize this skill's instructions and email-sending workflows in contexts where external communication or sensitive-data handling was not clearly requested.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

The skill gives actionable instructions for sending email, including code and API endpoints, but does not warn about privacy implications, recipient consent, data disclosure, or the fact that content will be transmitted to external recipients and Cloudflare services. In an agent setting, this omission can normalize outbound messaging and increase the risk of sending sensitive or unintended data without adequate user confirmation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/cli-and-mcp.md (reported line 116)May include surrounding context.

Or via REST API:

bash
curl "https://api.cloudflare.com/client/v4/accounts/${CLOUDFLARE_ACCOUNT_ID}/email/sending/send" \
  --header "Authorization: Bearer ${CLOUDFLARE_API_TOKEN}" \
  --header "Content-Type: application/json" \
  --data '{

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/deliverability.md (reported line 128)May include surrounding context.

Manually suppress an address:

bash
curl -X POST "https://api.cloudflare.com/client/v4/accounts/{account_id}/email/sending/suppression" \
  --header "Authorization: Bearer <API_TOKEN>" \
  --header "Content-Type: application/json" \
  --data '{ "email": "user@example.com", "expires_at": "2026-06-01T00:00:00Z" }'

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/deliverability.md (reported line 263)May include surrounding context.

Note: emailSendingAdaptive filters use datetime_geq/datetime_leq (Time type, e.g. "2026-04-01T00:00:00Z"), while emailSendingAdaptiveGroups uses date_geq/date_leq (Date type, e.g. "2026-04-01").

curl example:

bash
curl "https://api.cloudflare.com/client/v4/graphql" \

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 72)May include surrounding context.

Endpoint

text
POST https://api.cloudflare.com/client/v4/accounts/{account_id}/email/sending/send

Authentication

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/cli-and-mcp.md (reported line 116)May include surrounding context.

Endpoint

text
POST https://api.cloudflare.com/client/v4/accounts/{account_id}/email/sending/send

Authentication

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/deliverability.md (reported line 79)May include surrounding context.

Endpoint

text
POST https://api.cloudflare.com/client/v4/accounts/{account_id}/email/sending/send

Authentication

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/deliverability.md (reported line 100)May include surrounding context.

Endpoint

text
POST https://api.cloudflare.com/client/v4/accounts/{account_id}/email/sending/send

Authentication

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/deliverability.md (reported line 128)May include surrounding context.

Endpoint

text
POST https://api.cloudflare.com/client/v4/accounts/{account_id}/email/sending/send

Authentication

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/deliverability.md (reported line 139)May include surrounding context.

Endpoint

text
POST https://api.cloudflare.com/client/v4/accounts/{account_id}/email/sending/send

Authentication

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/deliverability.md (reported line 266)May include surrounding context.

Endpoint

text
POST https://api.cloudflare.com/client/v4/accounts/{account_id}/email/sending/send

Authentication

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/rest-api.md (reported line 10)May include surrounding context.

Endpoint

text
POST https://api.cloudflare.com/client/v4/accounts/{account_id}/email/sending/send

Authentication

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/rest-api.md (reported line 47)May include surrounding context.

Endpoint

text
POST https://api.cloudflare.com/client/v4/accounts/{account_id}/email/sending/send

Authentication

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/rest-api.md (reported line 62)May include surrounding context.

Endpoint

text
POST https://api.cloudflare.com/client/v4/accounts/{account_id}/email/sending/send

Authentication

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · references/rest-api.md (reported line 80)May include surrounding context.

Endpoint

text
POST https://api.cloudflare.com/client/v4/accounts/{account_id}/email/sending/send

Authentication

Static analysis

No suspicious patterns detected.