Cloudflare open sources a six-phase security-audit skill for coding agents
alexcovo_eth · x · 2026-09-24
Cloudflare has open sourced security-audit-skill, a coding-agent skill that turns your agent into a security auditor. It picked up 2,400+ GitHub stars in a single day (20.7k total).
The skill orchestrates isolated agents through six phases:
- Reconnaissance: maps architecture, trust boundaries, and input surfaces into architecture.md and a coverage ledger
- Coverage-led hunting: assigns isolated hunters from ledger units, with coverage critics surfacing gaps
- Candidate validation: a fresh verifier tries to disprove each unique candidate
- Structured output: confirmed / needsvalidation / rejected findings with independent record verification and target-neutral reporting
It's the single-repo starting point that grew into Cloudflare's fleet-wide vulnerability discovery harness, documented in the accompanying 'Build your own vulnerability harness' post.
Related event: Cloudflare Open-Sources Security Audit Skill for Coding Agents(2 posts)→
More from coding & agent
- Reading an invoice and moving money should not share one permission: agent auth principles — TechNadu · 2026-09-24
- Dev jokes about adding 'digest context when agitated' to every agents.md — nptacek · 2026-09-24
- ComfyUI Launches Comfy Router: One API for Image, Video, 3D and Audio Models — cpaik · 2026-09-24
- Agent ignored the GitHub plugin for computer use — fixed by adding a rule to AGENTS.md — jdjohnson · 2026-09-24
- Hamel Husain's AI Evals FAQ: model benchmarks and product evals answer different questions — HamelHusain · 2026-09-24
- Open-source MCP server gives agents page-change tracking with SHA-256 capture certificates — Einperegrin · 2026-09-24