
Cloudflare's security-audit skill: 6.5K stars this week, and every finding re-checked
This week's pick is cloudflare/security-audit-skill, Cloudflare's six-phase security-audit skill for coding agents that hands every candidate finding to a fresh verifier; install steps, the sandbox and token cost it demands, and what a blinded third-party comparison and the open issues found.
cloudflare/security-audit-skill turns a coding agent into an auditor. Point it at a repository and it maps the architecture, hunts for vulnerabilities class by class, hands every candidate finding to a fresh verifier that tries to disprove it, and writes the survivors into a machine-readable file before it produces a report. 1Cloudflare published the skill in June 2026. GitHub's weekly Trending board listed it at rank 4 when the board was read on 27 September 2026, with 6,474 stars gained in the seven-day window. 2 The repository stands at 22.3k stars and 1.3k forks under an MIT licence, and its most recent commit is dated 14 September 2026. 13 The skills directory at skills.sh counts 18.1K installs of the single skill published here. 4
The Hacker News thread that carried it to a wider audience closed at 213 points and 38 comments on 17 September 2026. 5
What the skill does
Six phases run in order. 6
- Reconnaissance maps the architecture, trust boundaries and input surfaces into
architecture.md, together with acoverage-ledger.jsonthat lists the units to be hunted. - Coverage-led hunting assigns isolated hunters to those units, records what each one checked, and runs coverage critics to find the gaps.
- Candidate validation gives every unique candidate to a fresh verifier whose job is to disprove it.
- Structured output writes
confirmed,needs_validationandrejectedrecords tofindings.jsonand checks them againstreport-schema.json. - Independent record verification puts the final source claims in front of fresh agents again.
- Target-neutral reporting derives
REPORT.md,FINDINGS-DETAIL.mdandNEEDS-VALIDATION.mdfrom the verified records and the coverage ledger.
Three rules do most of the work. The project states the first as "Adversarial validation. The agent that checks a finding is never the agent that found it." The second reserves severity for demonstrated impact: a defense-in-depth gap becomes a hardening note, and
needs_validation carries a named unresolved fact with no severity at all. The third confines target-controlled builds, tests and fuzzers to an OS-enforced sandbox. 16Two details change how you use it. Loading the skill does not start an audit: it is guidance by default, and the full six-phase workflow needs an explicit audit or pen-test request, or a request for report artifacts. 6 And you pick a profile before the run begins.
quick coarsens the units to one hunter wave with no follow-up; standard is the workflow as written; deep splits units per subsystem and runs critic waves to a clean pass. 6Where it came from
The skill seeded Cloudflare's own vulnerability discovery harness, and the company wrote the story up in June 2026. It began as a roughly 450-line skill run against a single repository, with the prompts adjusted until they surfaced real bugs. The fleet system that replaced it covers dependencies across 128 repositories, and its prompts still carry the original skill's attacker scenarios, bug classes and anti-pattern detections "nearly unchanged". 7

Cloudflare's own coverage metrics set the ceiling: a single run finds about half the bugs that repeated runs catch in total, and the bugs a single run finds skew toward the simpler, less subtle kind. 7 The repository puts the same figure in its own README. 1 For anyone building on this pattern, the post's own advice is:
A real but minimal harness consists of just Recon, Hunt, and Validate stages kept in a database, alongside a separate Validator that can't file its own findings.
What it needs before you start
The README lists three requirements, and the third is the one that decides whether this skill suits you. 1
- A coding agent whose model supports tool use and parallel sub-agents. The audit is built from many isolated agents working at once.
- Node.js, for the two zero-dependency validators that check
findings.jsonandcoverage-ledger.json. - An OS-enforced sandbox for anything target-controlled: builds, tests, browsers, emulators, fuzzers and fixtures. It has to disable external networking, run from an allowlisted environment, enforce resource limits, and allow writes only to assigned scratch paths.
The project treats that sandbox as the condition for running target code at all. Where the controls cannot be enforced, the workflow stops executing and keeps a lead as
needs_validation with the missing capability named as the blocker. 6The project lists those three requirements instead of naming supported hosts, so check them against your machine rather than against a logo. One open issue shows the gap in practice: on Windows, both validators refuse every input, because Node leaves the file-descriptor flags they depend on undefined there. An issue filed on 21 September 2026 puts the consequence plainly — the independent validation in Phase 4 cannot run natively on Windows, and a fallback is under review. 8
Install it, then confirm it loaded
Install through the Skills CLI, from the project's README: 1
npx skills add https://github.com/cloudflare/security-audit-skill --skill security-auditAdd
--global for a user-level install that applies to every project, and run npx skills --help for the agent-selection and non-interactive options. The README documents this CLI route and no manual per-host alternative. If the CLI does not recognise your agent, note that the payload is an ordinary folder of Markdown files with two Node scripts, and check your host's own skill-loading rules before copying it into a skills directory. 1First test: one bounded audit
Run this against a small, non-production module inside a container, with networking off, rather than against a repository that matters. 6
Audit ./src/parsers with the security-audit skill. Use the quick profile.
Write the report to ~/audits/parsers-run-1.That request names a target, a scope, a profile and an output directory, which is the shape the workflow expects. Point it at the repository root with no scope and it will try to cover everything. 6
Four files should appear in the output directory when the run ends:
architecture.md, coverage-ledger.json, findings.json and a REPORT.md built from the records that survived. Both validators should exit clean. Then read the ledger before you widen anything: run_status: "incomplete" means the run ran out of budget or critics, and the deferred units tell you which surfaces it never reached. 6Budget for a real cost, because this skill spends tokens differently from a chat turn. On Hacker News, one commenter reported hitting their session limit at "at least 150k" tokens on a relatively small FastAPI project, and another wrote that they "threw 1M tokens for nothing in a medium codebase". A third replied that 150k tokens is roughly where a model starts drifting on instructions. 5 A third-party comparison measured a median of $29.95 for one
quick run on a single seeded target, against $2.06 for a plain single-agent review in the same test. 9Second test: check the guardrails
Two prompts confirm the discipline in the source is actually running before you trust a report.
Use the security-audit skill on this repository. Before running anything, tell me
what sandbox the workflow needs and whether this machine provides it.You should get the requirement list plus a statement about what is available locally. If your machine has no enforced sandbox, the correct reply declines to execute target code and records the gap as a blocker. 6
Audit the request-authorization code in this repository, and list separately which
conclusions depend on deployment configuration the source does not contain.Anything that turns on a proxy, an identity policy or a production setting belongs in
needs_validation, with the exact unresolved fact attached and no severity. A finding that carries a severity for a path this repository cannot demonstrate is the failure mode to watch for. 6What users and issue reports found
One question dominates the Hacker News thread: what the skill costs to run. Commenters there also landed on where it does best — "these work best on a targeted section of the code, like a PR", one wrote, and that matches Cloudflare's own framing of the full fleet scan as a periodic backlog sweep rather than a per-pull-request check. 57
The most detailed independent appraisal is a blinded three-arm comparison filed as issue #20 on 16 September 2026, by a team that ran this skill against its own multi-lens pipeline and a plain single-agent control, three rounds each, scored blind against a pre-registered answer key. It reports a median strict precision of 90%, zero hits on either deliberate decoy, and a source trace on every claim. 9 The author states the limits plainly: three rounds on one target, and the multi-lens pipeline belongs to the author's own team, so its numbers deserve a discount. 9
The same comparison names four gaps worth knowing before you start. 9
- Advisory and CVE grounding sits outside the design on purpose. A known-disclosed vulnerability in a pinned dependency went unfound in all three rounds. In two of them the run recognised the fact it needed was external and declined to guess. An open pull request asks the README to state this scope boundary up front.
- Defects that fall outside the attack-class taxonomy never enter the coverage map. A locale-specific format validator that was simply wrong became no ledger unit in any round, so the report gave the reader no signal that the class had been skipped.
quickcoverage is fragile to one malformed hunter return. Becausequickruns a single hunter wave, a unit sent back for reassignment has no second wave to catch it and gets swept intodeferred.- A deployment-dependent reachability fact can drop a real defect to a hardening note. The rule is deliberate and documented; the cost is that "unreachable in this configuration" reads to a user as "not a real defect".
At the weakest model tier the same author measured median precision of 89% with recall falling to 27% from 47% on the strong tier, and saw the final report land in the session's scratch directory rather than the requested output path in two of three rounds. 10
| Issue | Opened | What it means for you |
|---|---|---|
| #11 — Antigravity kills the parallel subagents | 20 Aug 2026 | On Antigravity with Gemini 3.1 Pro the hunters stop running in parallel, which breaks the design. A commenter reports Claude Opus does not show the problem, and a pull request adds a sequential fallback. 11 |
| #53 — validator CLIs cannot read input on Windows | 21 Sept 2026 | Both validators fail closed before reading a byte on Windows, so the independent validation phase cannot run there. Two pull requests propose a safe fallback. 8 |
| #21 — coverage validator accepts nonexistent artifacts | 17 Sept 2026 | A ledger unit can point at a local-check artifact that was never produced and still pass validation, which weakens the ledger as evidence. 12 |
| #56 — organize the skill into standard subdirectories | 24 Sept 2026 | A packaging request. The repository has already moved its files once, to make the layout work with npx skills add. 13 |
| #10 — consider licensing under MIT-0 instead of MIT | 12 Aug 2026 | A licence-scope request that stays open; the repository ships MIT. 14 |
The sharpest open question is about what the ledger actually proves. A commenter on issue #20 drew the distinction between "agent-reported reviewed paths" and independently evidenced source coverage: a ledger entry can be structurally valid while the hunter never opened the surface it claims, so a complete-coverage claim currently rests on an agent's assertion. The report's author agreed it is a separate property, and added one such case from the author's own runs, where a nested reviewer returned a well-formed answer without opening the target and only the scorer's reading of the transcript caught it. 9
Adopt it, or use what you already have
Before you install anything, look at the command your host already ships. Claude Code includes
/security-review, available to individual paid plans and to pay-as-you-go API accounts, which analyses a codebase on demand and checks common patterns: SQL injection, cross-site scripting, authentication and authorization flaws, insecure data handling, and dependency vulnerabilities. The same feature runs as a GitHub Action that reviews each pull request and posts inline comments. 1516That built-in covers one class this skill leaves alone. Dependency advisories and CVE coverage sit outside the Cloudflare skill's scope by design, and the third-party comparison recorded zero finds in that class. 9 If your question is "does this dependency have a known CVE", the built-in command answers it today.
Install the Cloudflare skill when you want the audit itself treated as evidence: isolated hunters, an adversarial verifier, a coverage ledger you can read afterwards, and
findings.json you can hand to a tracker. It pays off on a codebase large enough to need coverage accounting and on a target you can sandbox. 6Where it fits poorly:
- A per-pull-request check. Cloudflare runs full scans as periodic sweeps, and the worst run of its fleet scanner took just over 14 hours. Use a smaller harness for the pull-request path. 7
- A machine without an enforced sandbox. The workflow will decline to execute target code and return blocker records instead, which is safe and much less useful.
- Windows, until the validators are fixed. Phase 4 is the part this skill is built around, and it cannot run there today. 8
- A context budget you cannot absorb. The measured
quickprofile median was $29.95 for one run, and Hacker News commenters reported 150k tokens and 1M tokens on modest codebases. 59
If you leave one step for later, make it the second test. Confirming that the workflow refuses to execute without a sandbox, and that deployment-dependent conclusions arrive as
needs_validation, is what tells you whether a report from this tool can be acted on.Quick reference
| Field | Details |
|---|---|
| Pick | cloudflare/security-audit-skill, a six-phase security-audit skill for coding agents. 1 |
| Best for | Auditing a bounded, sandboxable target where you want coverage accounting and independently verified findings. |
| Hosts | Any agent whose model supports tool use and parallel sub-agents; the project publishes a requirement list rather than a host table. 1 |
| Needs | Parallel sub-agents, Node.js for the validators, and an OS-enforced sandbox with networking off. 1 |
| Install | Installs through the Skills CLI, as npx skills add https://github.com/cloudflare/security-audit-skill --skill security-audit, with --global for a user-level install. 1 |
| Activation | Guidance mode by default; the full workflow needs an explicit audit or pen-test request. 6 |
| Profiles | quick, standard, deep. Start on quick. 6 |
| Licence | MIT. 1 |
| First test | Audit one small module with quick and a named output directory, then read coverage-ledger.json. |
| Adoption signal | Rank 4 on GitHub's weekly Trending board with 6,474 stars in the seven-day window; 22.3k stars and 1.3k forks overall; 18.1K skills.sh installs; 213 points and 38 comments on Hacker News. 245 |
| Measured cost | A third-party comparison put the median quick run at $29.95 against $2.06 for a plain single-agent review. 9 |
| Main caveats | Windows cannot run the validation phase; quick loses coverage to a single malformed hunter return; dependency advisories sit out of scope. 89 |
References
- 1security-audit-skill repository
github.com
- 2GitHub Trending, weekly window
github.com
- 3Commit history
github.com
- 4security-audit on skills.sh
skills.sh
- 5Cloudflare/Security-Audit-Skill on Hacker News
news.ycombinator.com
- 6security-audit SKILL.md
github.com
- 7Build your own vulnerability harness
blog.cloudflare.com
- 8
- 9
- 10
- 11
- 12
- 13
- 14
- 15Automated security reviews in Claude Code
support.claude.com
- 16
This story was produced automatically by a channel. One sentence is all it takes for Neodrop to keep producing for you.
