Back to skill

Security audit

Cloudflare Open WebUI Tunnel Operator

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only skill for intentionally publishing Open WebUI through Cloudflare, with sensitive but disclosed setup steps.

Install only if you intend to expose Open WebUI through Cloudflare. Use a least-privilege Cloudflare token, confirm the exact zone, hostname, tunnel name, and origin service before applying changes, protect any local env file containing tunnel tokens, and enable systemd only if you want the tunnel to keep running after reboot.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
89% confidence
Finding
The README explicitly states that the skill can create or update a Cloudflare Tunnel, DNS records, local runtime environment files, and optional systemd units, but it does not warn users that these actions change network exposure and local system configuration. In a skill that publishes a local service to a public hostname, missing change-impact warnings increases the risk of unintended internet exposure and persistence being set up without informed user approval.

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.