integrating-recaptcha-transaction-defense

Pass

Audited by Gen Agent Trust Hub on Mar 26, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill requires running local Node.js scripts (assets/check-status.js and assets/verify-logic.js) to verify API connectivity and integration correctness. These scripts use official client libraries and are part of the skill's own assets for development verification.
  • [EXTERNAL_DOWNLOADS]: The skill references the official Google reCAPTCHA Enterprise script (google.com/recaptcha/enterprise.js) and instructs the user to install standard, well-known Node.js packages including @google-cloud/recaptcha-enterprise, stripe, and express. All resources originate from trusted vendors.
  • [PROMPT_INJECTION]: The skill instructs the agent to survey the user's project structure and environment files to adapt code snippets to the existing framework (e.g., React, Vue). This data ingestion is used for benign code generation and configuration matching rather than decision-making that could be manipulated for malicious purposes.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 26, 2026, 03:36 PM