Cloudflare/Security-Audit-Skill (github.com)

67 points by donk8r 6 hours ago

14 comments:

by prodigycorp 3 hours ago

Hi Cloudflare people, if you are reading this. Please clean up your Cloudflare. Skills. There are way too many skills for the platform. You should consolidate all of your skills into a single skill and route everything thru that skill. The way it is right now pollutes our context window.

https://github.com/cloudflare/skills/tree/main/skills

by m00dy 2 hours ago

I'm sure they read here.

by dewey an hour ago

They actually do.

by gbrindisi an hour ago

Shameless plug: in case someone finds this requiring too many tokens, we shared the recipe on how we built our own in house audit skill so that it can easily be replicated and tuned to different environments https://www.synthesia.io/post/automating-code-security-revie...

by drchaim 4 hours ago

I threw 1M tokens for nothing in a medium codebase.

by TZubiri 3 hours ago

how much is medium codebase, like 50kloc including docs?

by drchaim an hour ago

in this case medium is relative to the projects I've worked. Bad expression anyway.

by throwup238 2 hours ago

500kloc plus at least ten million lines of gastown logs.

For a todo cli. That doesn’t work.

by this_user an hour ago

Welcome to agentic coding in 2026.

by 9el an hour ago

Any clues why "an OS-enforced sandbox" is in requirements?

by nicce 11 minutes ago

Probably to save their skin if agent starts to do some unexpected things and bringing havoc. But I doubt that OpenAI models with normal subscription, for example, wont even work with this skill.

by hyperionultra 5 hours ago

Uf, how much tokens?

by jesse_dot_id 4 hours ago

At least 150k on my relatively small FastAPI project, but hit my session limit. Continuing in a few hours.

Data from: Hacker News, provided by Hacker News (unofficial) API