turnstile-spin

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFECREDENTIALS_UNSAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPERSISTENCE
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill's setup wizard in SKILL.md suggests three methods for a user to provide their CLOUDFLARE_API_TOKEN. One of these methods involves pasting the token directly into the chat interface, which exposes the high-privilege secret to the conversation history and potential logging systems. While the skill includes a warning for the user to rotate the token, the instruction itself promotes a risky practice.
  • [INDIRECT_PROMPT_INJECTION]: The skill performs automated scans of the project environment (e.g., package.json, wrangler.toml, README.md) to extract domain information and framework types. This ingestion of untrusted local data represents a surface for indirect prompt injection, which could influence the agent's orchestration logic.
  • Ingestion points: package.json, wrangler.toml, README.md, AGENTS.md, and application source files scanned for framework detection (Step 6 of SKILL.md).
  • Boundary markers: Absent from the codebase scan instructions.
  • Capability inventory: The skill possesses significant capabilities including the ability to write files (Frontend edits), deploy Cloudflare Workers, and execute shell scripts with Account-level API permissions.
  • Sanitization: Scripts use jq and python3 for structured JSON parsing, but no explicit sanitization is performed on the data extracted from scanned files before it is used to influence the agent's plan.
  • [EXTERNAL_DOWNLOADS]: The scripts/persist-skill.sh and scripts/worker-deploy.sh scripts utilize npx degit to fetch the skill bundle and managed Worker templates from the official Cloudflare skills repository on GitHub (github.com/cloudflare/skills). These downloads target a well-known service and a trusted organization.
  • [COMMAND_EXECUTION]: The skill relies on several shell scripts that invoke system commands and CLI tools such as wrangler, curl, python3, jq, openssl, and chmod. These are used for legitimate configuration, authentication probing, widget creation via the Cloudflare API, and Worker deployment.
  • [PERSISTENCE]: The skill includes a persistence mechanism in scripts/persist-skill.sh that saves the skill's instructions and scripts to the local filesystem (e.g., .claude/skills/). This ensures the skill remains available to the agent across different sessions or projects.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:56 PM
Security Audit — agent-trust-hub — turnstile-spin