首页 > AI前沿 > Cloudflare/Security-Audit-Skill

Cloudflare/Security-Audit-Skill

Hacker News 2026-09-17 12:36 2 阅读 查看原文
security-audit A coding-agent skill that turns your agent into a security auditor. It orchestrates isolated agents through reconnaissance, coverage-led hunting, candidate validation, structured output, independent record verification, and target-neutral reporting. This is the skill that seeded Cloudflare's vulnerability discovery harness, described in Build your own vulnerability harness. The harness grew into a multi-stage, fleet-wide system; this skill is the single-repo starting point it evolved from. What it does The skill runs a structured audit in six phases: Reconnaissance -- map architecture, trust boundaries, input surfaces, prior evidence, and deterministic coverage in architecture.md and coverage-ledger.json. Coverage-led hunting -- assign isolated hunters from ledger units, record their checks, and use coverage critics to find gaps. Candidate validation -- give every unique candidate to a fresh verifier that tries to disprove it. Structured output -- write confirmed, needs_validation, and rejected records to findings.json and validate them against report-schema.json. Independent record verification -- fresh agents verify final source claims. Material replacements receive another independent verifier. Target-neutral reporting -- derive REPORT.md, FINDINGS-DETAIL.md, and NEEDS-VALIDATION.md from the verified records and coverage ledger. The parent runs validate-coverage-ledger.cjs after creating the ledger and after each later ledger update. It runs validate-findings.cjs in Phase 4 and again after every Phase 5 replacement. The verdicts are distinct: confirmed has a complete source trace and bounded observed result, needs_validation has an exact unresolved fact and no severity, and rejected records a disproved candidate. Multiple runs against the same repo are additive. The skill uses prior ledgers and findings to target gaps, revalidate changed source, and carry forward current-source evidence without treating stale or unresolved work as covered. Files Installation Install the skill with the Skills CLI: npx skills add https://github.com/cloudflare/security-audit-skill \ --skill security-audit Use --global for a user-level installation: npx skills add https://github.com/cloudflare/security-audit-skill \ --skill security-audit \ --global Run npx skills --help for agent-selection and non-interactive options. Usage Start your coding agent in (or pointed at) the codebase you want to audit, then ask it to do a security audit: security audit this codebase find security vulnerabilities in ./src do a security review, output to ~/audits/my-project The skill activates automatically when the request matches its trigger (security audit, find vulnerabilities, pen-test the code, etc.). A direct codebase audit or pen-test request uses full audit mode. Security questions and focused vulnerability work use guidance mode unless you request report artifacts. In full audit mode, an unspecified output directory defaults to ~/security-audit-skill/ /run- . The workflow writes inside the target repository only when you explicitly select a directory that version control ignores. Requirements A coding agent with a model that supports tool use and parallel sub-agents Node.js for the zero-dependency findings and coverage-ledger validators An OS-enforced sandbox for target-controlled builds, tests, processes, browsers, emulators, fuzzers, and fixtures. It must disable external networking, use a sanitized allowlisted environment, enforce resource limits, and allow writes only to assigned scratch paths. Without these controls, the workflow keeps the lead as needs_validation instead of executing target code. Design principles Only confirm established boundary failures. Keep a source-grounded blocked lead as needs_validation with its exact unresolved fact. Adversarial validation. The agent that checks a finding is never the agent that found it. Severity requires impact. Likelihood x impact, not deviation from a checklist. Defense-in-depth gaps are not vulnerabilities. If Layer A prevents the attack, the absence of Layer B is a hardening note. Multiple runs improve coverage. In our test runs, a single run found roughly half of the vulnerabilities that repeated runs found in total. Contact Questions, feedback, or comparing notes on AI-driven security tooling: security-ai-research@cloudflare.com License MIT -- see LICENSE.