turnstile-spin
Pass
Audited by Gen Agent Trust Hub on Sep 27, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill executes several local shell scripts located in a
scripts/directory and utilizes thewranglerCLI to manage Cloudflare infrastructure and deployment secrets. - [EXTERNAL_DOWNLOADS]: The skill facilitates communication with official Cloudflare API endpoints (
api.cloudflare.com) and supports installing thewranglerpackage throughnpmif missing from the user's environment. - [INDIRECT_PROMPT_INJECTION]: The skill scans local codebase files, such as
package.jsonandREADME.md, to automatically detect domains and project metadata. This represents a surface for ingesting untrusted data, although the skill mitigates risk by requiring user confirmation of the detected parameters and review of all code diffs. - Ingestion points: Reads
package.json,README.md,AGENTS.md, and git remote metadata inSKILL.md. - Boundary markers: Not explicitly defined for the scanning process, but the skill enforces a mandatory user confirmation step before every irreversible action.
- Capability inventory: Includes shell script execution, API requests via
curlandwrangler, and file system writes for frontend edits and skill persistence. - Sanitization: Relies on the user to review unified diffs before applying any changes to the codebase.
- [CREDENTIALS_UNSAFE]: The skill handles Cloudflare API tokens and Turnstile secrets. It provides secure guidance for users, such as using environment variables or restricted local files (
umask 077), and explicitly instructs the agent not to log or persist secret keys to disk.
Audit Metadata