Cloudflare Open-Sources Six-Phase Security Audit Skill for Coding Agents
Cloudflare released an open-source coding agent skill that transforms tools like Claude Code into automated security auditors. It runs a structured six-phase pipeline using adversarial validation and isolated sub-agents to trace and verify vulnerabilities.

Impact: High
Why it matters
You can now run comprehensive, adversarial penetration testing on your codebases using an off-the-shelf skill without building custom agent harnesses.
TL;DR
- 01Separates vulnerability hunters from verifiers to eliminate AI self-confirmation bias
- 02Multiple runs against identical repositories roughly doubled the detected issue count
- 03Requires zero dependencies beyond Node.js for validation utilities
Key facts
- Audit Phases
- 6 structured phases
- Coverage Multiplier
- ~2x more vulnerabilities found across repeated runs (self-reported)
- Dependency Count
- 0 external runtime dependencies for validators
Six-Phase Adversarial Pipeline
Cloudflare's security-audit-skill orchestrates sub-agents through a strict verification lifecycle: 1. Reconnaissance: Maps architecture, trust boundaries, and input attack surfaces into architecture.md and coverage-ledger.json. 2. Coverage-Led Hunting: Assigns isolated hunter agents to discrete ledger units with coverage critics checking for gaps. 3. Candidate Validation: Each lead is handed to an independent verifier whose sole job is disproving the attack vector. 4. Structured Output: Writes records categorized as confirmed, needs_validation, or rejected against a rigid JSON schema. 5. Independent Record Verification: Fresh agents re-verify source-level evidence. 6. Target-Neutral Reporting: Compiles actionable summaries in REPORT.md and FINDINGS-DETAIL.md.
Strict Sandboxing and Execution Requirements
The harness strictly demands an OS-enforced execution sandbox. Target code compilation, fixtures, and local fuzzers must run without outbound network access and with write privileges confined solely to temporary scratch directories. If sandboxing is unavailable, the harness downgrades leads to needs_validation rather than executing unchecked code.
Try it in 2 minutes
npx skills add https://github.com/cloudflare/security-audit-skill --globalbash
✓ When to use
- Deep automated security reviews and penetration testing before deploying releases
- Systematic vulnerability mapping of untrusted third-party dependencies
✕ When NOT to use
- When running in an un-sandboxed environment with production credentials or sensitive network access
- Quick superficial code sanity checks where a simple linter suffices
What to do today
- Install the skill globally with npx skills add https://github.com/cloudflare/security-audit-skill --global
- Ensure your coding environment runs inside an OS-enforced sandbox before launching full repository audits
- Trigger the audit with 'do a security review, output to ~/audits/my-project' in your agent terminal
Sources