cloudflare/security-audit-skill

Source
GitHub
First trending
Category
Security
GitHub stars
22,749
Main language
JavaScript

This page introduces an external open-source repository. It is not an HDATF product.

cloudflare/security-audit-skill

What it does

A coding-agent skill that runs a six-phase security audit of a repository. Isolated agents map the architecture, hunt for issues and try to disprove each candidate, and results are written as schema-validated findings and reports.

How it helps ATF

Its use of fresh verifier agents that try to disprove each finding, with confirmed, needs_validation and rejected records, is worth comparing with how Harness checks a result with evidence before handing it back.

License

MIT Permissive. Commercial use and changes are allowed if the copyright notice is kept.

More in this category

  • scadastrangelove/awesome-ai-security-tools
    A curated catalog of public-source, research, and commercial tools for AI security and AI-assisted cybersecurity. Topics include agent security, supply-chain security, scanners, runtime protection, and evaluation frameworks.
  • NationalSecurityAgency/ghidra
    Ghidra is a software reverse engineering framework created and maintained by the NSA Research Directorate. It analyzes compiled code with disassembly, decompilation, graphing and scripting, and supports many processor instruction sets and executable formats.
  • hwdsl2/wireguard-install
    A WireGuard VPN server installer for several Linux distributions. It supports automated or interactive setup, client profile and QR code generation, user management, and IPv4 and IPv6 clients.
  • guillaumemeyer/watermarks-remover
    An agent skill plus a Python service that strips AI provenance marks from content you own, such as invisible Unicode characters, statistical text watermarks and C2PA, EXIF or XMP metadata in files. The skill calls the service over HTTP.
  • mvt-project/mvt
    A mobile forensic toolkit for collecting traces of possible Android and iOS compromise and checking public indicators of compromise. It is intended for investigators with forensic expertise, not end-user self-assessment.

Only repositories in the ranked Trendshift lists are included, and the lists are used only to find candidates. We do not copy their ranks. Descriptions, licenses and star counts come from each GitHub repository. The notes are our own reading. We have not tested these projects, and a place on a trending list does not prove quality.

View on GitHub (opens in a new tab)