Cloudflare open-sources security-audit-skill, a six-phase coding-agent vulnerability harness
evilsocket · x · 2026-09-22
Cloudflare open-sourced security-audit-skill (19.4k stars on GitHub), a coding-agent skill that turns your agent into a security auditor — the single-repo starting point that grew into Cloudflare's fleet-wide vulnerability discovery harness. It orchestrates isolated agents through six phases:
- Reconnaissance: maps architecture, trust boundaries, and input surfaces into architecture.md and coverage-ledger.
- Coverage-led hunting: assigns isolated hunters from ledger units, with coverage critics to find gaps
- Candidate validation: every unique candidate goes to a fresh verifier that tries to disprove it
- Structured output: confirmed / needsvalidation / rejected findings
- Independent record verification and target-neutral reporting
A directly reusable reference for security teams and agent engineers alike.
More from coding & agent
- Developer uses Codex computer use to navigate Austria's messy FinanzOnline tax portal — kevinkern · 2026-09-22
- Multi-agent group chats: drop a task at night, run 10+ agents unattended, review by morning — huangyun_122 · 2026-09-22
- 7 open-source repos for scraping millions of web pages, from Scrapling to ScrapeGraphAI — JafarNajafov · 2026-09-22
- If agents can shop for you, agent-native rivals will replace Zomato, Amazon and Blinkit — vaibhavbetter · 2026-09-22
- Refunds, fraud signals and high-stakes calls: where should agent autonomy stop? — ConvertMyStore · 2026-09-22
- Obsidian Starter Kit v4 turns your vault into an AI workspace with 375 skills and MCP server — dSebastien · 2026-09-22