google-recaptcha

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the installation of the @membranehq/cli package from the NPM registry, which is the official command-line interface for the Membrane platform.
  • [COMMAND_EXECUTION]: Shell commands are used to perform login operations, manage application connections, and execute reCAPTCHA actions through the Membrane CLI.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a data ingestion surface as it processes assessments and records from Google reCAPTCHA.
  • Ingestion points: Data enters the context through results returned from membrane action run and membrane request commands (SKILL.md).
  • Boundary markers: The skill documentation does not specify explicit delimiters for the agent to use when processing API response data.
  • Capability inventory: The skill uses the Membrane CLI for network operations, authenticated API requests, and connection management.
  • Sanitization: Authentication, token lifecycle, and secure proxying are handled by the Membrane platform infrastructure rather than local scripts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 03:11 AM
Security Audit — agent-trust-hub — google-recaptcha