用 Claude Code 或 Codex 调用 Cloudflare
Holy shit, tell Claude Code or Codex "security audit this codebase" in your proj…
结构清晰,直接给出具体操作指令、覆盖的检查维度以及官方测试中的关键数据(单次运行覆盖率),对开发者有实际参考价值。
Holy shit, tell Claude Code or Codex "security audit this codebase" in your project, and it spins up a batch of agents to hunt for vulnerabilities, then hands every suspected issue to 𝗮 𝗳𝗿𝗲𝘀𝗵 𝗮𝗴𝗲𝗻𝘁 𝘁𝗵𝗮𝘁 𝘁𝗿𝗶𝗲𝘀 𝘁𝗼 𝗱𝗶𝘀𝗽𝗿𝗼𝘃𝗲 𝗶𝘁. Cloudflare's vulnerability-hunting harness grew out of this open-source skill, and the repo picked up 20K stars in September alone.
天哪,在你的项目中告诉 Claude Code 或 Codex "安全审计这个代码库",它会启动一批代理来搜寻漏洞,然后将每个疑似问题交给一个试图证伪它的崭新代理。Cloudflare 的漏洞搜寻工具包源于这项开源技能,该仓库仅在九月就获得了 20K 星标。
It checks: - Data isolation: can one user's data leak into another's - Login and auth - Prompt injection and agent tool calls - Dependencies and CI - Cloud permissions and config - Plus client-side, memory safety, resource exhaustion, and more
它检查: - 数据隔离:一个用户的数据是否会泄露到另一个用户 - 登录和认证 - 提示注入和代理工具调用 - 依赖项和 CI - 云权限和配置 - 以及客户端、内存安全、资源耗尽等更多内容
Findings come out as confirmed, needs validation, or ruled out. In Cloudflare's own tests, a single run found 𝗼𝗻𝗹𝘆 𝗮𝗯𝗼𝘂𝘁 𝗵𝗮𝗹𝗳 of what several runs found together, so run it more than once. Without a sandbox, issues that can only be confirmed by running your code stay at "needs validation." Your model needs to run subagents in parallel, and Opus 5.5 and Sol in Codex both can.
发现结果分为已确认、需验证或已排除。在 Cloudflare 自己的测试中,单次运行仅发现了多次运行共同发现的大约一半内容,因此请多次运行。如果没有沙箱环境,只能通过运行代码才能确认的问题将停留在“需验证”状态。你的模型需要并行运行子代理,Codex 中的 Opus 5.5 和 Sol 都可以做到。
npx skills add cloudflare/security-audit-skill --skill security-audit https://github.com/cloudflare/security-audit-skill
更进一步:量化金融体系
看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力