AI product Open source · MIT

security-audit

security-audit is a Cloudflare coding-agent skill that orchestrates multi-phase security audits of codebases. It uses reconnaissance to map architecture, trust boundaries, input surfaces, prior evidence, and deterministic coverage; assigns isolated agents to coverage-led hunting; sends each unique candidate to a fresh verifier; and records confirmed, needs_validation, and rejected results in machine-readable findings.json validated against a report schema. Independent agents verify final source claims, after which the skill derives target-neutral reports and coverage records. It can be installed with the Skills CLI and requires a tool-using coding agent with parallel sub-agent support, Node.js for its validators, and an OS-enforced sandbox for target-controlled execution. The repository is licensed under MIT.

View repository Mentioned in 1 video ↓

What security-audit is used for

1 use taken from transcripts — each links to the moment in the video.

  • A Cloudflare skill that makes a coding agent perform a structured security audit of a codebase using multiple phases, isolated agents, validation, and sandboxing.

Videos mentioning security-audit

1 in the library.