Back to skill

Security audit

Sandbox Sdk

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only Cloudflare Sandbox SDK helper with expected sandbox lifecycle, file, command, and port-exposure guidance, and no hidden execution or persistence behavior.

Install this if you are working with Cloudflare Sandbox SDK or sandboxed code execution. Treat destroy(), deleteFile(), exec(), package installation, and exposed preview ports as powerful sandbox operations: use user- or session-scoped sandbox IDs and confirm destructive cleanup when preserving sandbox state matters.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description says to load this skill when "building AI code execution, code interpreters, CI/CD systems, interactive dev environments, or executing untrusted code," which spans several broad, common software tasks without clear boundaries or exclusion conditions. This makes invocation scope ambiguous and increases the chance the skill is selected for loosely related requests.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

This markdown file describes sandbox.destroy() as immediately terminating and deleting all state, but provides no warning or cautionary note for users about irreversible data loss. The same reference style presents these operations as neutral API calls, which omits safety-critical disclosure expected for destructive behaviors in markdown documentation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
81% confidence
Finding

The file documents writeFile, mkdir, and deleteFile operations, including deletion, but does not include any warning that these calls change or remove filesystem contents. For markdown skill documentation, omission of warnings about behaviors affecting user data or system integrity is in scope for this rule.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

Low
Category
Tool Misuse
Confidence
15% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 130)May include surrounding context.

RUN npm install -g typescript

System packages

RUN apt-get update && apt-get install -y ffmpeg && rm -rf /var/lib/apt/lists/*

EXPOSE 8080 # Required for local dev port exposure

text

Tool Parameter Abuse

Low
Category
Tool Misuse
Confidence
15% confidence
Finding

Tool parameters are crafted to achieve unintended or unsafe behavior. Parameter abuse can bypass intended safety checks (e.g. shell=True, --force, dangerous glob patterns).

Content

Scanner excerpt · SKILL.md (reported line 130)May include surrounding context.

RUN npm install -g typescript

System packages

RUN apt-get update && apt-get install -y ffmpeg && rm -rf /var/lib/apt/lists/*

EXPOSE 8080 # Required for local dev port exposure

text

Chaining Abuse

Low
Category
Tool Misuse
Confidence
15% confidence
Finding

Tool calls are chained to bypass individual safety checks or escalate capabilities beyond what any single tool call would allow.

Content

Scanner excerpt · SKILL.md (reported line 130)May include surrounding context.

RUN npm install -g typescript

System packages

RUN apt-get update && apt-get install -y ffmpeg && rm -rf /var/lib/apt/lists/*

EXPOSE 8080 # Required for local dev port exposure

text

Static analysis

No suspicious patterns detected.