Cloudflare security-audit-skill
Multi-phase coding-agent security audit producing independently verified, machine-readable findings.
🛡️ AgentReady threat assessment
MAESTRO 7-layer threat model + OWASP AIVSS risk score for Cloudflare security-audit-skill, derived from its capabilities.
These scores are auto-generated from public information (the agent's own listing, docs, and repository) using the canonical OWASP AIVSS formula and the MAESTRO framework — an estimate for guidance, not a penetration test, audit, or certification. See the scoring methodology — every score is re-derived by the same automated method as an agent's public evidence changes.
Overview
A Cloudflare-published Agent Skill for running structured, multi-phase security audits of a codebase, where each finding is independently verified and emitted in a machine-readable format. It orchestrates audit phases and bundles the verification logic. Reads the target codebase and can run bundled scripts, making its execution surface security-relevant.
Key features and capabilities
- Multi-phase audit workflow
- Independently verified findings
- Machine-readable output
Use cases
- Run a security audit on a repo
- Produce verifiable vulnerability findings