Cloudflare Security Audit
Agent SkillA source-first audit workflow for finding and validating security issues in codebases. It emphasizes concrete trust boundaries, evidence-backed findings, scoped coverage, bounded testing, and independent verification.
How to use it
Ask for a focused security review or request a full codebase audit. For a full audit, specify the repository, paths in scope, and report location. Target-controlled builds and tests should run only inside the Skill’s required OS-enforced sandbox, with external networking blocked, resources limited, and writes confined to scratch space. If those controls or the needed agent capabilities are unavailable, report the blocker rather than treating a check as verified.
Compatibility
The source does not explicitly name supported agents, so compatibility is not listed.
Limitations noted
- A full audit depends on parallel agent support, Node.js validators, and an OS-enforced sandbox; the Skill does not provide those capabilities.
- The full workflow also relies on companion methodology documents and validators in the source repository; this directory record links only to the pinned SKILL.md.
- If the required sandbox controls are unavailable, the workflow says not to execute target-controlled code and to report the missing control as needs-validation.