What it is
A skill that turns Claude Code, or another coding agent, into a structured security auditor. Cloudflare says it's the single-repo starting point that grew into its own fleet-wide vulnerability discovery harness.
How it works
- Recon. It maps your architecture, trust boundaries and everywhere input comes in.
- Hunting. Separate “hunter” agents work through a coverage list, so nothing gets checked twice or skipped.
- Validation. Every possible bug goes to a fresh agent whose job is to prove it isn't real.
- Structured output. Each finding is recorded as confirmed, needs validation or rejected, and checked against a schema.
- Verification. New agents re-check the final claims against the source.
- Reports. You get
REPORT.md,FINDINGS-DETAIL.mdandNEEDS-VALIDATION.md.
Why it matters
- Vibe-coded apps rarely get a security review. This gives you a structured one for free.
- The disprove step cuts false alarms. A finding only counts if a separate agent fails to knock it down.
- Runs build on each other. Run it again and it targets the gaps from last time.
Get started
npx skills add https://github.com/cloudflare/security-audit-skill --skill security-auditAdd --global to install it for every project. Then open Claude Code in the project and ask:
security audit this codebaseBefore you use it
- Expect heavy usage on a big codebase. It runs many agents across six phases, so try it on a small repo first.
- Findings still need a human. “Needs validation” items are unresolved on purpose; read them before you act.
- Only audit code you own or have permission to test.