Cloudflare has made a new security audit tool available on GitHub, designed to help developers evaluate code for vulnerabilities. This tool introduces a unique approach by separating the process into two main roles: hunters, who identify potential issues, and verifiers, who evaluate the findings independently. The system includes three possible outcomes for each report: "confirmed," which means a vulnerability was clearly found; "needs_validation," which indicates more information is required; and "rejected," which means the report doesn’t meet the necessary criteria.
The GitHub repository includes files that categorize different types of attacks, such as memory corruption, prompt injection, and tenant isolation. It also provides a JSON schema that defines the structure of a security report and two JavaScript-based validators that check whether the evidence meets the required format. These validators operate without external dependencies, making the tool easy to use and integrate.
The audit process follows six distinct phases, beginning with reconnaissance—mapping the system’s architecture and identifying key components—and ending with the final report. After mapping the system, the tool generates a coverage matrix to guide the audit. Then, it sends out independent "hunters" to analyze each part of the system. Each finding is then reviewed by a verifier who has not been involved in the initial search, ensuring unbiased evaluation.
The tool is designed to prevent certain undesirable behaviors, such as an agent modifying the code to create an exploit or suggesting a test that might be misinterpreted as a critical flaw. These scenarios are avoided through specific instructions that guide the agent’s behavior. To use the tool, users need to install the Vercel Labs skills CLI and run the audit on their repository. The report is saved outside the audited code to avoid unintended changes, and the system includes safeguards to prevent unintended code execution unless a sandbox environment is manually set up.
Cloudflare notes that running the audit locally may take significantly longer than in their internal systems, which can handle large codebases efficiently. The tool may also require multiple runs to find all vulnerabilities, as each pass typically detects about half of the issues. The Cloudflare Security Audit Skill is available under the MIT license and requires Node.js to run, with detailed instructions provided in the SKILL.md file for compatibility and setup.
Cloudflare Releases Security Audit Skill for Code Review on GitHub
AI-rewritten from original reportingHow it works
cloudflaresecurity-auditgithubcode-analysisvalidatorssandbox
Original sources:
- 🇫🇷Korben



