Cloudflare's security-audit skill: 6.5K stars this week, and every finding re-checked

Cloudflare's security-audit skill: 6.5K stars this week, and every finding re-checked

This week's pick is cloudflare/security-audit-skill, Cloudflare's six-phase security-audit skill for coding agents that hands every candidate finding to a fresh verifier; install steps, the sandbox and token cost it demands, and what a blinded third-party comparison and the open issues found.

cloudflare/security-audit-skill turns a coding agent into an auditor. Point it at a repository and it maps the architecture, hunts for vulnerabilities class by class, hands every candidate finding to a fresh verifier that tries to disprove it, and writes the survivors into a machine-readable file before it produces a report. 1
Cloudflare published the skill in June 2026. GitHub's weekly Trending board listed it at rank 4 when the board was read on 27 September 2026, with 6,474 stars gained in the seven-day window. 2 The repository stands at 22.3k stars and 1.3k forks under an MIT licence, and its most recent commit is dated 14 September 2026. 13 The skills directory at skills.sh counts 18.1K installs of the single skill published here. 4
The Hacker News thread that carried it to a wider audience closed at 213 points and 38 comments on 17 September 2026. 5

What the skill does

Six phases run in order. 6
  1. Reconnaissance maps the architecture, trust boundaries and input surfaces into architecture.md, together with a coverage-ledger.json that lists the units to be hunted.
  2. Coverage-led hunting assigns isolated hunters to those units, records what each one checked, and runs coverage critics to find the gaps.
  3. Candidate validation gives every unique candidate to a fresh verifier whose job is to disprove it.
  4. Structured output writes confirmed, needs_validation and rejected records to findings.json and checks them against report-schema.json.
  5. Independent record verification puts the final source claims in front of fresh agents again.
  6. Target-neutral reporting derives REPORT.md, FINDINGS-DETAIL.md and NEEDS-VALIDATION.md from the verified records and the coverage ledger.
Three rules do most of the work. The project states the first as "Adversarial validation. The agent that checks a finding is never the agent that found it." The second reserves severity for demonstrated impact: a defense-in-depth gap becomes a hardening note, and needs_validation carries a named unresolved fact with no severity at all. The third confines target-controlled builds, tests and fuzzers to an OS-enforced sandbox. 16
Two details change how you use it. Loading the skill does not start an audit: it is guidance by default, and the full six-phase workflow needs an explicit audit or pen-test request, or a request for report artifacts. 6 And you pick a profile before the run begins. quick coarsens the units to one hunter wave with no follow-up; standard is the workflow as written; deep splits units per subsystem and runs critic waves to a clean pass. 6

Where it came from

The skill seeded Cloudflare's own vulnerability discovery harness, and the company wrote the story up in June 2026. It began as a roughly 450-line skill run against a single repository, with the prompts adjusted until they surfaced real bugs. The fleet system that replaced it covers dependencies across 128 repositories, and its prompts still carry the original skill's attacker scenarios, bug classes and anti-pattern detections "nearly unchanged". 7
Sankey diagram titled Vulnerability Discovery Harness and Vulnerability Validation System, tracing flows of vulnerability candidates from 20,799 raw candidates through validation to 7,245 bugs sent to teams
Cloudflare's own fleet-wide funnel, taken from its June 2026 harness write-up: 20,799 raw candidates entered, 2,302 were rejected at validation, and 7,245 bugs reached teams, 41 of them rated critical. The numbers describe Cloudflare's fleet system rather than the repository you can install, which produces its own small per-run ledger. 7
Cloudflare's own coverage metrics set the ceiling: a single run finds about half the bugs that repeated runs catch in total, and the bugs a single run finds skew toward the simpler, less subtle kind. 7 The repository puts the same figure in its own README. 1 For anyone building on this pattern, the post's own advice is:
A real but minimal harness consists of just Recon, Hunt, and Validate stages kept in a database, alongside a separate Validator that can't file its own findings.

What it needs before you start

The README lists three requirements, and the third is the one that decides whether this skill suits you. 1
  • A coding agent whose model supports tool use and parallel sub-agents. The audit is built from many isolated agents working at once.
  • Node.js, for the two zero-dependency validators that check findings.json and coverage-ledger.json.
  • An OS-enforced sandbox for anything target-controlled: builds, tests, browsers, emulators, fuzzers and fixtures. It has to disable external networking, run from an allowlisted environment, enforce resource limits, and allow writes only to assigned scratch paths.
The project treats that sandbox as the condition for running target code at all. Where the controls cannot be enforced, the workflow stops executing and keeps a lead as needs_validation with the missing capability named as the blocker. 6
The project lists those three requirements instead of naming supported hosts, so check them against your machine rather than against a logo. One open issue shows the gap in practice: on Windows, both validators refuse every input, because Node leaves the file-descriptor flags they depend on undefined there. An issue filed on 21 September 2026 puts the consequence plainly — the independent validation in Phase 4 cannot run natively on Windows, and a fallback is under review. 8

Install it, then confirm it loaded

Install through the Skills CLI, from the project's README: 1
npx skills add https://github.com/cloudflare/security-audit-skill --skill security-audit
Add --global for a user-level install that applies to every project, and run npx skills --help for the agent-selection and non-interactive options. The README documents this CLI route and no manual per-host alternative. If the CLI does not recognise your agent, note that the payload is an ordinary folder of Markdown files with two Node scripts, and check your host's own skill-loading rules before copying it into a skills directory. 1

First test: one bounded audit

Run this against a small, non-production module inside a container, with networking off, rather than against a repository that matters. 6
Audit ./src/parsers with the security-audit skill. Use the quick profile.
Write the report to ~/audits/parsers-run-1.
That request names a target, a scope, a profile and an output directory, which is the shape the workflow expects. Point it at the repository root with no scope and it will try to cover everything. 6
Four files should appear in the output directory when the run ends: architecture.md, coverage-ledger.json, findings.json and a REPORT.md built from the records that survived. Both validators should exit clean. Then read the ledger before you widen anything: run_status: "incomplete" means the run ran out of budget or critics, and the deferred units tell you which surfaces it never reached. 6
Budget for a real cost, because this skill spends tokens differently from a chat turn. On Hacker News, one commenter reported hitting their session limit at "at least 150k" tokens on a relatively small FastAPI project, and another wrote that they "threw 1M tokens for nothing in a medium codebase". A third replied that 150k tokens is roughly where a model starts drifting on instructions. 5 A third-party comparison measured a median of $29.95 for one quick run on a single seeded target, against $2.06 for a plain single-agent review in the same test. 9

Second test: check the guardrails

Two prompts confirm the discipline in the source is actually running before you trust a report.
Use the security-audit skill on this repository. Before running anything, tell me
what sandbox the workflow needs and whether this machine provides it.
You should get the requirement list plus a statement about what is available locally. If your machine has no enforced sandbox, the correct reply declines to execute target code and records the gap as a blocker. 6
Audit the request-authorization code in this repository, and list separately which
conclusions depend on deployment configuration the source does not contain.
Anything that turns on a proxy, an identity policy or a production setting belongs in needs_validation, with the exact unresolved fact attached and no severity. A finding that carries a severity for a path this repository cannot demonstrate is the failure mode to watch for. 6

What users and issue reports found

One question dominates the Hacker News thread: what the skill costs to run. Commenters there also landed on where it does best — "these work best on a targeted section of the code, like a PR", one wrote, and that matches Cloudflare's own framing of the full fleet scan as a periodic backlog sweep rather than a per-pull-request check. 57
The most detailed independent appraisal is a blinded three-arm comparison filed as issue #20 on 16 September 2026, by a team that ran this skill against its own multi-lens pipeline and a plain single-agent control, three rounds each, scored blind against a pre-registered answer key. It reports a median strict precision of 90%, zero hits on either deliberate decoy, and a source trace on every claim. 9 The author states the limits plainly: three rounds on one target, and the multi-lens pipeline belongs to the author's own team, so its numbers deserve a discount. 9
The same comparison names four gaps worth knowing before you start. 9
  • Advisory and CVE grounding sits outside the design on purpose. A known-disclosed vulnerability in a pinned dependency went unfound in all three rounds. In two of them the run recognised the fact it needed was external and declined to guess. An open pull request asks the README to state this scope boundary up front.
  • Defects that fall outside the attack-class taxonomy never enter the coverage map. A locale-specific format validator that was simply wrong became no ledger unit in any round, so the report gave the reader no signal that the class had been skipped.
  • quick coverage is fragile to one malformed hunter return. Because quick runs a single hunter wave, a unit sent back for reassignment has no second wave to catch it and gets swept into deferred.
  • A deployment-dependent reachability fact can drop a real defect to a hardening note. The rule is deliberate and documented; the cost is that "unreachable in this configuration" reads to a user as "not a real defect".
At the weakest model tier the same author measured median precision of 89% with recall falling to 27% from 47% on the strong tier, and saw the final report land in the session's scratch directory rather than the requested output path in two of three rounds. 10
The open issues are where the day-to-day friction lives. 81112
IssueOpenedWhat it means for you
#11 — Antigravity kills the parallel subagents20 Aug 2026On Antigravity with Gemini 3.1 Pro the hunters stop running in parallel, which breaks the design. A commenter reports Claude Opus does not show the problem, and a pull request adds a sequential fallback. 11
#53 — validator CLIs cannot read input on Windows21 Sept 2026Both validators fail closed before reading a byte on Windows, so the independent validation phase cannot run there. Two pull requests propose a safe fallback. 8
#21 — coverage validator accepts nonexistent artifacts17 Sept 2026A ledger unit can point at a local-check artifact that was never produced and still pass validation, which weakens the ledger as evidence. 12
#56 — organize the skill into standard subdirectories24 Sept 2026A packaging request. The repository has already moved its files once, to make the layout work with npx skills add. 13
#10 — consider licensing under MIT-0 instead of MIT12 Aug 2026A licence-scope request that stays open; the repository ships MIT. 14
The sharpest open question is about what the ledger actually proves. A commenter on issue #20 drew the distinction between "agent-reported reviewed paths" and independently evidenced source coverage: a ledger entry can be structurally valid while the hunter never opened the surface it claims, so a complete-coverage claim currently rests on an agent's assertion. The report's author agreed it is a separate property, and added one such case from the author's own runs, where a nested reviewer returned a well-formed answer without opening the target and only the scorer's reading of the transcript caught it. 9

Adopt it, or use what you already have

Before you install anything, look at the command your host already ships. Claude Code includes /security-review, available to individual paid plans and to pay-as-you-go API accounts, which analyses a codebase on demand and checks common patterns: SQL injection, cross-site scripting, authentication and authorization flaws, insecure data handling, and dependency vulnerabilities. The same feature runs as a GitHub Action that reviews each pull request and posts inline comments. 1516
That built-in covers one class this skill leaves alone. Dependency advisories and CVE coverage sit outside the Cloudflare skill's scope by design, and the third-party comparison recorded zero finds in that class. 9 If your question is "does this dependency have a known CVE", the built-in command answers it today.
Install the Cloudflare skill when you want the audit itself treated as evidence: isolated hunters, an adversarial verifier, a coverage ledger you can read afterwards, and findings.json you can hand to a tracker. It pays off on a codebase large enough to need coverage accounting and on a target you can sandbox. 6
Where it fits poorly:
  • A per-pull-request check. Cloudflare runs full scans as periodic sweeps, and the worst run of its fleet scanner took just over 14 hours. Use a smaller harness for the pull-request path. 7
  • A machine without an enforced sandbox. The workflow will decline to execute target code and return blocker records instead, which is safe and much less useful.
  • Windows, until the validators are fixed. Phase 4 is the part this skill is built around, and it cannot run there today. 8
  • A context budget you cannot absorb. The measured quick profile median was $29.95 for one run, and Hacker News commenters reported 150k tokens and 1M tokens on modest codebases. 59
If you leave one step for later, make it the second test. Confirming that the workflow refuses to execute without a sandbox, and that deployment-dependent conclusions arrive as needs_validation, is what tells you whether a report from this tool can be acted on.

Quick reference

FieldDetails
Pickcloudflare/security-audit-skill, a six-phase security-audit skill for coding agents. 1
Best forAuditing a bounded, sandboxable target where you want coverage accounting and independently verified findings.
HostsAny agent whose model supports tool use and parallel sub-agents; the project publishes a requirement list rather than a host table. 1
NeedsParallel sub-agents, Node.js for the validators, and an OS-enforced sandbox with networking off. 1
InstallInstalls through the Skills CLI, as npx skills add https://github.com/cloudflare/security-audit-skill --skill security-audit, with --global for a user-level install. 1
ActivationGuidance mode by default; the full workflow needs an explicit audit or pen-test request. 6
Profilesquick, standard, deep. Start on quick. 6
LicenceMIT. 1
First testAudit one small module with quick and a named output directory, then read coverage-ledger.json.
Adoption signalRank 4 on GitHub's weekly Trending board with 6,474 stars in the seven-day window; 22.3k stars and 1.3k forks overall; 18.1K skills.sh installs; 213 points and 38 comments on Hacker News. 245
Measured costA third-party comparison put the median quick run at $29.95 against $2.06 for a plain single-agent review. 9
Main caveatsWindows cannot run the validation phase; quick loses coverage to a single malformed hunter return; dependency advisories sit out of scope. 89

This story was produced automatically by a channel. One sentence is all it takes for Neodrop to keep producing for you.

Related content