// Skill profile
cloudflare/security-audit-skill is an open-source coding-agent skill for automated multi-phase security audits. Derived from Cloudflare's internal vulnerability discovery harness, it orchestrates a fleet of isolated sub-agents through six phases: recon, hunting, validation, reporting, structured output, and independent verification. Each finding is machine-readable and independently verified by a separate agent pass, reducing false positives. Drop it into any compatible coding agent (Claude Code, Codex, Cursor) and point it at a codebase to get a structured security audit. The skill handles the orchestration — spinning up specialized sub-agents for different vulnerability classes, coordinating their findings, and producing a consolidated report with severity ratings and reproduction steps. +3,162 stars/day on GitHub Trending. 16.4K total stars. MIT licensed.
Cloudflare Security Audit Skill is the open-sourced starting point of Cloudflare’s internal vulnerability discovery harness. Instead of running a single security scan, it orchestrates multiple isolated sub-agents through a six-phase pipeline: reconnaissance (mapping the attack surface), hunting (searching for vulnerability classes), validation (confirming exploitability), reporting (structuring findings), structured output (machine-readable JSON), and independent verification (a separate agent pass that re-checks each finding).
The multi-phase approach with independent verification is the key differentiator. Most automated security tools produce long lists of potential issues with high false-positive rates. By having a separate verification agent independently confirm each finding, the skill produces reports where flagged issues are more likely to be real, exploitable vulnerabilities rather than theoretical concerns.
Six-phase audit pipeline: The skill breaks security auditing into distinct phases, each handled by specialized sub-agents. This mirrors how experienced security teams work — reconnaissance before hunting, validation before reporting — but automates the coordination.
Independent verification: Every finding goes through a separate verification pass by an agent that did not participate in the initial discovery. This adversarial structure reduces false positives and increases confidence in the final report.
Machine-readable output: Findings are structured as JSON with severity ratings, affected code locations, reproduction steps, and remediation suggestions. This makes it straightforward to integrate into CI/CD pipelines or security dashboards.
Agent-agnostic installation: The skill is a structured instruction set (Markdown + JavaScript validators) that works with any coding agent that supports skill installation — Claude Code, Codex CLI, or Cursor.
Security-conscious development teams use the skill to run automated security audits before releases. Open-source maintainers use it to audit contributions and dependencies. Penetration testers use it as a starting point for more targeted manual testing. DevSecOps teams integrate it into CI pipelines for continuous security validation.
The skill requires a capable underlying model to perform effective security analysis — it orchestrates the audit but the quality of findings depends on the model’s security knowledge. Running a full six-phase audit on a large codebase consumes significant tokens due to the multi-agent architecture. The independent verification phase adds cost but substantially improves signal-to-noise ratio. MIT licensed, no Cloudflare account required.
Security engineers who want automated, structured vulnerability discovery. Development teams that need security audits integrated into their agent workflows. Anyone building on Cloudflare’s reference harness pattern for multi-agent security analysis.
AI agents that work well with Cloudflare Security Audit Skill.
817 structured cybersecurity skills for AI agents — mapped to MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, and NIST AI RMF.
Reverse engineering via MCP — AI agents can decompile, analyze, and understand binary code using Ghidra.
150+ cybersecurity tools accessible via MCP — pentesting, vulnerability scanning, OSINT, and more.