Maaz
All guides

/audit

Cloudflare's security audit skill, free to run on your own code.

The skill that seeded Cloudflare's own bug-hunting harness. Agents hunt for vulnerabilities, then a fresh agent tries to disprove each one.

What it is

A skill that turns Claude Code, or another coding agent, into a structured security auditor. Cloudflare says it's the single-repo starting point that grew into its own fleet-wide vulnerability discovery harness.

How it works

  1. Recon. It maps your architecture, trust boundaries and everywhere input comes in.
  2. Hunting. Separate “hunter” agents work through a coverage list, so nothing gets checked twice or skipped.
  3. Validation. Every possible bug goes to a fresh agent whose job is to prove it isn't real.
  4. Structured output. Each finding is recorded as confirmed, needs validation or rejected, and checked against a schema.
  5. Verification. New agents re-check the final claims against the source.
  6. Reports. You get REPORT.md, FINDINGS-DETAIL.md and NEEDS-VALIDATION.md.

Why it matters

  • Vibe-coded apps rarely get a security review. This gives you a structured one for free.
  • The disprove step cuts false alarms. A finding only counts if a separate agent fails to knock it down.
  • Runs build on each other. Run it again and it targets the gaps from last time.

Get started

Terminal
npx skills add https://github.com/cloudflare/security-audit-skill --skill security-audit

Add --global to install it for every project. Then open Claude Code in the project and ask:

Claude Code
security audit this codebase

Before you use it

  • Expect heavy usage on a big codebase. It runs many agents across six phases, so try it on a small repo first.
  • Findings still need a human. “Needs validation” items are unresolved on purpose; read them before you act.
  • Only audit code you own or have permission to test.

Get the next guide by email.

One email when a new guide or launch goes up. No spam, and you can unsubscribe from any email.