turnstile-spin

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes several local shell scripts located in a scripts/ directory and utilizes the wrangler CLI to manage Cloudflare infrastructure and deployment secrets.
  • [EXTERNAL_DOWNLOADS]: The skill facilitates communication with official Cloudflare API endpoints (api.cloudflare.com) and supports installing the wrangler package through npm if missing from the user's environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill scans local codebase files, such as package.json and README.md, to automatically detect domains and project metadata. This represents a surface for ingesting untrusted data, although the skill mitigates risk by requiring user confirmation of the detected parameters and review of all code diffs.
  • Ingestion points: Reads package.json, README.md, AGENTS.md, and git remote metadata in SKILL.md.
  • Boundary markers: Not explicitly defined for the scanning process, but the skill enforces a mandatory user confirmation step before every irreversible action.
  • Capability inventory: Includes shell script execution, API requests via curl and wrangler, and file system writes for frontend edits and skill persistence.
  • Sanitization: Relies on the user to review unified diffs before applying any changes to the codebase.
  • [CREDENTIALS_UNSAFE]: The skill handles Cloudflare API tokens and Turnstile secrets. It provides secure guidance for users, such as using environment variables or restricted local files (umask 077), and explicitly instructs the agent not to log or persist secret keys to disk.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 06:53 PM
Security Audit — agent-trust-hub — turnstile-spin