Audit Your Vibe-Coded App
Apps built fast with AI tend to ship with the same holes: API keys left exposed, auth that can be bypassed, database and API endpoints that trust too much. Cloudflare has open-sourced the security-audit skill it built to hunt bugs across its own fleet. Install it in Claude Code, ask it to "security audit this codebase," and it puts a team of AI agents to work on your code.
A Team of Agents Hunts Your Code
The skill maps your project, then deploys isolated sub-agents, each hunting a different attack family:
- exposed API keys and secrets
- auth bypass and broken access control
- insecure database and API code, and injection
- prompt injection
It follows a six-phase workflow — from recon through hunting, validation and reporting — so coverage is systematic rather than random. Cloudflare used the same skill to scan its own fleet of 128 repositories.
A Skeptic Verifies Every Bug
Before anything reaches the report, a separate skeptic agent that took no part in the hunt tries to disprove each finding. What survives is a list of verified vulnerabilities, with the exact lines to fix. The skill is MIT-licensed and agent-neutral.
Know Its Limits
By default the report is written outside your repository. It's a tool, not a guarantee: review the findings yourself. It reduces risk; it doesn't make your app bulletproof. Run it on code you own or are authorized to audit.
What's in the Guide
What the skill hunts for, how the hunt-then-skeptic workflow works, the install command for Claude Code, where the report goes, and a direct link to the repo.
The full field guide is in the PDF.
Get the Guide
Drop your email below and we'll send it straight to your inbox.