Back to plugin

Security audit

Cloudflare Unified Billing (CF AI Gateway)

Security checks for vulnerabilities and agentic risk

Overview

This package is a coherent Cloudflare AI Gateway provider plugin with disclosed credential and network use for model access, web search, web fetch, and image generation.

Install only if you intend to route model, search, fetch, and image requests through Cloudflare AI Gateway. Use least-privilege Cloudflare tokens, be aware that prompts and requested URLs/images go to the configured gateway or custom domain, and review any custom domain or Access credentials before enabling them.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

Detected: suspicious.env_credential_access, suspicious.exposed_secret_literal

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
dist/index.js:1723
Evidence
const apiKey = normalizeOptionalString2(process.env[API_TOKEN_ENV_VAR]) ?? normalizeOptionalString2(params.scopedCredentialConfig?.cfAiGatewayApiKey) ?? normali...

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
README.md:114
Evidence
- With Access: `cf-access-token: [REDACTED]` (AI Gateway records the verified Access subject as `cf.user_id`)