2026-10-11 16:37 UTC

Cloudflare claims its released security-audit skill combines coverage-led hunting, separate adversarial verifiers, and schema-validated findings to make repeated coding-agent repository audits more complete and auditable.

state: watchingheat: lowuncertainty: mediumconvergesscott: highagentic-security agent-harnesses coding-agentsCloudflare

What is this?

Cloudflare has released security-audit-skill, a GitHub-hosted skill for coding agents that coordinates multi-phase repository security audits and advertises independently verified, machine-readable findings. Its repository describes parallel architecture and trust-boundary reconnaissance, vulnerability hunting, and separate agents tasked with disproving findings; it also claims one run finds roughly half the vulnerabilities found across multiple runs, without exposing the testing details in these snippets. Secondary posts describe six phases and say the skill seeded Cloudflare’s own vulnerability-hunting system, but the supplied primary snippet does not establish that provenance or schema validation.

Why it matters to Scott

Cloudflare’s released audit skill converges with Scott’s separate adversarial review pass and source-anchored WordPress security-review work, providing a concrete comparison tool and publishing opportunity rather than merely another orchestration example. The useful test is whether its disprover agents meet his mechanically-different-verifiers standard: the supplied grounding does not establish mechanical independence, schema validation, or reproducible coverage gains, and no supplied radar hit tracks this same release.
dev:project.wordpress-security-reviewdev:concept.claim-bounded-adversarial-verificationip:source.security-reviewer-method-ebookip:concept.mechanically-different-verifiersradar:vulnbench-repeatable-bug-discoveryradar:google-agentic-source-review-securityradar:concept.agentic-securityradar:concept.agent-verification
queries asked of Scott's wikis
  • coding-agent harnesses multi-phase orchestration
  • independent adversarial verification false positives
  • repeated agent runs coverage evaluation
  • schema-validated findings auditable agent outputs
  • repository security audits trust-boundary mapping

Measured heat

now 0 pts/hpeak 0 pts/hcomments 0/hpeers p14momentum: steady2 platformsage 587h
points/hour across evidence · reading as of 2026-10-12 02:59:37.977291+11:00 · deterministic, not a model opinion

How the heat travelled

09-17 05:21 (minted)⭐ origin echo-reconstructedCloudflare releases the single-repository skill that seeded its vulnerability-discovery harness, with six audit phases, independent finding
Cloudflare on github (echo) · attributed from hn.story.49736466 · published time unknown
—
09-17 04:36first on hacker news · published · lag ?Cloudflare/Security-Audit-Skill
donk8r
—
09-17 04:36amplified on hacker news 👑hn.story.49736466
donk8r
peak 213 · 38 comments · 100% of case engagement
09-17 05:20our radar first saw it · lag ?discovery anchor: hn.story.49736466—
pace: p77 vs 1032 stories at the 336h mark (now 587h old) — ahead of astra-vending-bench-results (1.0x), behind intern-decision-one-pass-decisions (1.0x)

Evidence (2) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnCloudflare/Security-Audit-Skill
Retrieved article excerpt

Open article · Retrieved 2026-09-17T05:21:38.155784+00:00

# security-audit

A coding-agent skill that turns your agent into a security auditor. It orchestrates isolated agents through reconnaissance, coverage-led hunting, candidate validation, structured output, independent record verification, and target-neutral reporting.

This is the skill that seeded Cloudflare's vulnerability discovery harness, described in [Build your own vulnerability harness](https://blog.cloudflare.com/build-your-own-vulnerability-harness). The harness grew into a multi-stage, fleet-wide system; this skill is the single-repo starting point it evolved from.

## What it does

The skill runs a structured audit in six phases:

1. **Reconnaissance** -- map architecture, trust boundaries, input surfaces, prior evidence, and deterministic coverage in `architecture.md` and `coverage-ledger.json`.
2. **Coverage-led hunting** -- assign isolated hunters from ledger units, record their checks, and use coverage critics to find gaps.
3. **Candidate validation** -- give every unique candidate to a fresh verifier that tries to disprove it.
4. **Structured output** -- write `confirmed`, `needs_validation`, and `rejected` records to `findings.json` and validate them against `report-schema.json`.
5. **Independent record verification** -- fresh agents verify final source claims. Material replacements receive another independent verifier.
6. **Target-neutral reporting** -- derive `REPORT.md`, `FINDINGS-DETAIL.md`, and `NEEDS-VALIDATION.md` from the verified records and coverage ledger.

The parent runs `validate-coverage-ledger.cjs` after creating the ledger and after each later ledger update. It runs `validate-findings.cjs` in Phase 4 and again after every Phase 5 replacement.

The verdicts are distinct: `confirmed` has a complete source trace and bounded observed result, `needs_validation` has an exact unresolved fact and no severity, and `rejected` records a disproved candidate.

Multiple runs against the same repo are additive. The skill uses prior ledgers and findings to target gaps, revalidate changed source, and carry forward current-source evidence without treating stale or unresolved work as covered.

## Files

| File | Purpose |
| --- | --- |
| `SKILL.md` | Setup, core principles, platform terminology, workflow overview, and audit anti-patterns |
| `RECONNAISSANCE.md` | Phase 1 reconnaissance prompts and synthesis instructions |
| `HUNTING.md` | Phase 2 orchestration, hunting methodology, and validation rules |
| `ATTACK-CLASSES.md` | Core, wildcard, and obvious-things attack prompts |
| `MEMORY-SAFETY-AND-BINARY.md` | Memory-safety, binary, and kernel hunting classes for native targets |
| `AI-AND-LLM.md` | Prompt-injection, agent/tool, and output-handling hunting classes for LLM-backed targets |
| `WEB-PROTOCOL-AND-AUTH.md` | HTTP request-framing, cache, and authentication-protocol hunting classes for HTTP-protocol and auth targets |
| `CLIENT-SIDE.md` | DOM-injection, messaging-trust, UI-redress, and prototype-pollution hunting classes for client-side/browser targets |
| `SUPPLY-CHAIN-AND-RELEASE.md` | Dependency, CI, release, signing, update, plugin, and extension hunting classes |
| `CLOUD-AND-DEPLOYMENT.md` | IAM, infrastructure-as-code, container, serverless, ingress, and runtime-configuration hunting classes |
| `PROTOCOLS-RPC-AND-MESSAGING.md` | RPC, serialization, queue, broker, webhook, and streaming-protocol hunting classes |
| `RESOURCE-EXHAUSTION-AND-AVAILABILITY.md` | Shared resource, quota, queue, worker, and operator-spend hunting classes |
| `DATA-ISOLATION-AND-LIFECYCLE.md` | Tenant isolation, cache, search, export, backup, migration, deletion, and restore hunting classes |
| `DESKTOP-MOBILE-AND-LOCAL-IPC.md` | Native app, deep-link, webview, exported-component, helper, daemon, and local-IPC hunting classes |
| `VALIDATION-AND-REPORTING.md` | Phases 3–6 candidate validation, structured output, record verification, and reporting |
| `report-schema.json` | JSON schema for all three `findings.json` verdicts |
| `validate-findings.cjs` | Zero-dependency validator for `findings.json` in Phases 4 and 5 |
| `validate-findings.test.cjs` | Findings-validator tests and producer-compatible fixture checks |
| `validate-coverage-ledger.cjs` | Zero-dependency validator for `coverage-ledger.json` in Phases 1–5 |
| `validate-coverage-ledger.test.cjs` | Coverage-ledger validator tests |

## Installation

Install the skill with the [Skills CLI](https://skills.sh):

```
npx skills add https://github.com/cloudflare/security-audit-skill \
  --skill security-audit
```

Use `--global` for a user-level installation:

```
npx skills add https://github.com/cloudflare/security-audit-skill \
  --skill security-audit \
  --global
```

Run `npx skills --help` for agent-selection and non-interactive options.

## Usage

Start your coding agent in (or pointed at) the codebase you want to audit, then ask it to do a security audit:

```
security audit this codebase
```

```
find security vulnerabilities in ./src
```

```
do a security review, output to ~/audits/my-project
```

The skill activates automatically when the request matches its trigger (security audit, find vulnerabilities, pen-test the code, etc.). A direct codebase audit or pen-test request uses full audit mode. Security questions and focused vulnerability work use guidance mode unless you request report artifacts. In full audit mode, an unspecified output directory defaults to `~/security-audit-skill/<repo-name>/run-<N>`. The workflow writes inside the target repository only when you explicitly select a directory that version control ignores.

## Requirements

- A coding agent with a model that supports tool use and parallel sub-agents
- Node.js for the zero-dependency findings and coverage-ledger validators
- An OS-enforced sandbox for target-controlled builds, tests, processes, browsers, emulators, fuzzers, and fixtures. It must disable external networking, use a sanitized allowlisted environment, enforce resource limits, and allow writes only to assigned scratch paths. Without these controls, the workflow keeps the lead as `needs_validation` instead of executing target code.

## Design principles

- **Only confirm established boundary failures.** Keep a source-grounded blocked lead as `needs_validation` with its exact unresolved fact.
- **Adversarial validation.** The agent that checks a finding is never the agent that found it.
- **Severity requires impact.** Likelihood x impact, not deviation from a checklist.
- **Defense-in-depth gaps are not vulnerabilities.** If Layer A prevents the attack, the absence of Layer B is a hardening note.
- **Multiple runs improve coverage.** In our test runs, a single run found roughly half of the vulnerabilities that repeated runs found in total.

## Contact

Questions, feedback, or comparing notes on AI-driven security tooling: [email protected]

## License

MIT -- see [LICENSE](https://github.com/cloudflare/security-audit-skill/blob/main/LICENSE).
donk8r21338
🟧 echo.github ⭐Cloudflare releases the single-repository skill that seeded its vulnerability-discovery harness, with six audit phases, independent finding Cloudflare——

Interpretation history

Decision trace