3 ms·
Cloudflare/Security-Audit-Skill
- hyperionultra 14d agoUf, how much tokens?
- jesse_dot_id 14d agoAt least 150k on my relatively small FastAPI project, but hit my session limit. Continuing in a few hours.
- chrisweekly 14d agoOof. YAGNI. 150k tokens is where you start hitting the "dumb zone" (model attention issues and inconsistent adherence to instructions).
- drchaim 14d agoI threw 1M tokens for nothing in a medium codebase.
- TZubiri 14d agohow much is medium codebase, like 50kloc including docs?
- throwup238 14d ago500kloc plus at least ten million lines of gastown logs. For a todo cli. That doesn’t work.
- this_user 14d agoWelcome to agentic coding in 2026.
- drchaim 14d agoin this case medium is relative to the projects I've worked. Bad expression anyway.
- TrustScoreAgent 14d ago[dead]
- SkyPuncher 14d agoThese work best on a targeted section of the code, like a PR.
- prodigycorp 14d agoHi Cloudflare people, if you are reading this. Please clean up your Cloudflare. Skills. There are way too many skills for the platform. You should consolidate all of your skills into a single skill and route everything thru that skill. The way it is right now pollutes our context window. https://github.com/cloudflare/skills/tree/main/skills https://github.com/cloudflare/skills/tree/main/skills
- m00dy 14d agoI'm sure they read here.
- dewey 14d agoThey actually do.
- m00dy 14d agoyeah I know :D
- bravetraveler 14d agoJohn Cloudflare: https://news.ycombinator.com/user?id=eastdakota https://news.ycombinator.com/user?id=eastdakota
- deleted 14d ago[deleted]
- kentonv 14d agoWe actually do. I forwarded this to the right person, and it sounds like it's being worked on. Thanks!
- tomrod 14d agoOnce again, proving my growing trust in Cloudflare is well placed. Thanks!
- 9el 14d agoAny clues why "an OS-enforced sandbox" is in requirements?
- nicce 14d agoProbably to save their skin if agent starts to do some unexpected things and bringing havoc. But I doubt that OpenAI models with normal subscription, for example, wont even work with this skill.
- donk8r 14d agoRuns target builds, tests, fuzzers. No sandbox: workflow won't execute them. Lead stays needs_validation.
- awss1i 13d ago[flagged]
- gbrindisi 14d agoShameless plug: in case someone finds this requiring too many tokens, we shared the recipe on how we built our own in house audit skill so that it can easily be replicated and tuned to different environments https://www.synthesia.io/post/automating-code-security-reviews-with-claude-mythos-level-capabilities https://www.synthesia.io/post/automating-code-security-revie...
- gyanchawdhary 14d agoThis is awesome. Thanks for sharing
- wslh 14d agoTip for security professionals using LLMs: audit skills that explicitly frame the task as security research sometimes trigger refusals from the top OpenAI and Anthropic models because they guard against misuse. What works for me: separate skills for bug classes (and bugs in general) without the security framing, plus another skill that combines their findings to spot security bugs.
- viraptor 14d agoIf you're a security professional, go through their validation. You won't get the security refusals anymore. Well... you'll still get the occasional downgrade from Fable, but not the "oh no, I can't do exploits for you" breaks.
- aitoolcrux 14d ago[flagged]
- tonymet 14d agoWhat’s the difference between a skill and a prompt? Separate files? Aren’t tokens, tokens?
- fassssst 14d agoSkills can have scripts packaged with them
- acedTrex 14d agoIncredible, a post and repo dedicated to a markdown file, the downfall of this field has been swift.
- vntok 14d agoDid you open the repo? There's a subdirectory with two dozens of files, around 300Kb of text. Storing/visualizing small text changes over time as revisions is exactly what Git is excellent at, how else would you keep track of updates to the prompts?
- acedTrex 14d ago> how else would you keep track of updates to the prompts I dont? because prompts are not a thing that are ever needed to be tracked lol.
- decidu0us9034 14d agobut they're very huge markdown files. look how much junk they're polluting the conext window with.
- qsbuilder 14d agoDumping 14 full schemas into the prompt is just lazy design. You burn tokens, spike latency for no reason