logo security-audit

security-audit

Cloudflare · AI Code Review & Security · Updated
Visit site

security-audit is the coding-agent skill that seeded Cloudflare's fleet-wide vulnerability discovery harness (described in the Cloudflare blog post "Build your own vulnerability harness"), released as a single-repo starting point. It orchestrates isolated agents through six phases: reconnaissance that maps architecture, trust boundaries, and input surfaces into `architecture.md` and a `coverage-ledger.json`; coverage-led hunting where isolated hunters attack ledger units and coverage critics look for gaps; candidate validation where a fresh verifier tries to disprove each finding; structured output of `confirmed`, `needs_validation`, and `rejected` records into a schema-validated `findings.json`; independent record verification of every source claim; and target-neutral `REPORT.md`, `FINDINGS-DETAIL.md`, and `NEEDS-VALIDATION.md` reports. Attack-class playbooks cover web protocol and auth, client-side, supply chain and release, cloud and deployment, RPC and messaging, resource exhaustion, data isolation, desktop/mobile/local IPC, memory safety and binaries, and prompt-injection and tool-use classes for LLM-backed targets. Repeat runs are additive, reusing prior ledgers and findings to target gaps and revalidate changed code.

Published by Cloudflare in 2026 alongside the "Build your own vulnerability harness" blog post; ~6.2k GitHub stars and trending on GitHub (daily) in mid-September 2026.

As of

  • Six-phase audit pipeline: recon, coverage-led hunting, adversarial validation, structured output, independent verification, reporting
  • Machine-readable `findings.json` validated against `report-schema.json` with distinct confirmed/needs_validation/rejected verdicts
  • Coverage ledger and validator scripts (`validate-coverage-ledger.cjs`, `validate-findings.cjs`)
  • Per-domain attack-class playbooks including AI/LLM prompt-injection and agent tool-use classes
  • Additive multi-run behavior that targets gaps and revalidates changed source
  • Battle-tested origin: the prompts that grew into Cloudflare's production vulnerability harness
✓ Best For

Security-minded engineering teams who want a rigorous, repeatable agent-driven security audit of a repository with verified, low-false-positive findings.

✗ Not Ideal For

Quick PR-level review or teams wanting a hosted SAST product with a UI; it is prompt-heavy and spends significant tokens. For inline PR review see Open Code Review, CodeRabbit, or Kodus; for classic SAST see Snyk Code.

Open Source

Free and open-source under MIT; installed as a skill into your existing coding agent. Cost is the model usage of the many parallel hunter, validator, and verifier agents it spawns.

One of the most credible open security-audit skills available, with a verification-first design that directly targets the false-positive problem plaguing agent security reviews.
securityvulnerability-discoveryagent-skillscode-auditclaude-codeopen-source
Is security-audit free?

Yes - security-audit is Open Source. Free and open-source under MIT; installed as a skill into your existing coding agent. Cost is the model usage of the many parallel hunter, validator, and verifier agents it spawns.

Is security-audit open source?

Yes - security-audit is open source. Free and open-source under MIT; installed as a skill into your existing coding agent. Cost is the model usage of the many parallel hunter, validator, and verifier agents it spawns.

Who is security-audit best for?

Security-minded engineering teams who want a rigorous, repeatable agent-driven security audit of a repository with verified, low-false-positive findings.

Who is security-audit not ideal for?

Quick PR-level review or teams wanting a hosted SAST product with a UI; it is prompt-heavy and spends significant tokens. For inline PR review see Open Code Review, CodeRabbit, or Kodus; for classic SAST see Snyk Code.

What are the best security-audit alternatives?

The closest security-audit alternatives on ai.dosa.dev are CodeRabbit, Qodo, Snyk Code - all listed under AI Code Review & Security.

Who makes security-audit?

security-audit is developed by Cloudflare. It is listed in the AI Code Review & Security category on ai.dosa.dev.

Track security-audit in your AI stack

Favorite this tool to revisit it later, or Zap it to contribute to the public vote count.

Content on this page is AI-generated. Please verify details with the vendor's website for accuracy.