turnstile-spin

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [Secret Management Controls]: The skill manages Cloudflare API tokens and Turnstile secrets using practices designed to minimize exposure. It explicitly instructs the agent to avoid pasting secrets into chat, uses terminal commands that prevent secrets from appearing in shell history (e.g., read -rsp), and verifies that .env files are included in .gitignore before writing to them.
  • [Infrastructure Interactions]: All network operations are directed toward official Cloudflare domains and GitHub repositories. These interactions are necessary for the skill's primary function of configuring Turnstile widgets and performing site verification.
  • [Indirect Prompt Injection Surface]: The skill scans local repository files (such as package.json and README.md) to detect frontend frameworks and backend handlers. While this introduces an ingestion point for potentially untrusted data, the instructions explicitly command the agent to treat repository text as untrusted and ensure it cannot alter the setup procedure or authorize secret writes.
  • [Verified Tool Usage]: To perform administrative tasks, the skill requires a user-approved version of the Wrangler CLI located outside the project directory. It restricts the use of project-local binaries or npx to prevent potential execution of unverified code from the project environment.
  • [Controlled Script Execution]: The skill utilizes several helper scripts for authentication probing and widget creation. These scripts use standard system utilities like bash, curl, and python3 for deterministic logic and JSON processing, operating with a 'fail-closed' approach where authentication or network failures stop the process.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:06 PM
Security Audit — agent-trust-hub — turnstile-spin