cloudflare-turnstile

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to load the Turnstile client-side library from Cloudflare's official content delivery network (CDN) at https://challenges.cloudflare.com/turnstile/v0/api.js.
  • [COMMAND_EXECUTION]: Includes a shell script scripts/check-csp.sh intended for users to verify that their website's Content Security Policy headers are compatible with Turnstile by inspecting headers via curl.
  • [REMOTE_CODE_EXECUTION]: Provides code templates for Cloudflare Workers, Hono, and React that perform server-side validation by communicating with Cloudflare's Siteverify API at https://challenges.cloudflare.com/turnstile/v0/siteverify.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 06:12 PM
Security Audit — agent-trust-hub — cloudflare-turnstile