Find the security holes in your AI-built app, free
Cloudflare open-sourced the AI skill it made to check its own code. Point it at your app and it hunts for weak logins, leaked data and other holes, then tells you how to fix them.
Checked on 9 Oct 2026. Tools change fast, so the official page always wins if it says something different.
What it does
- Maps your whole app first: its parts, logins, inputs and where data flows.
- Sends separate AI agents hunting for holes, each checking a different area (logins, data access, APIs, AI prompt injection and more).
- Double-checks every finding. A fresh agent tries to prove each problem wrong, so you mostly see real ones.
- Writes a report (REPORT.md plus the details) with what's confirmed, what still needs checking, and how to fix it.
- It's the skill that started Cloudflare's own vulnerability-hunting system.
What you need first
Step by step
Install Node.js and Claude Code
Download Node.js (LTS) from nodejs.org and install it. Then open Terminal (Cmd + Space, type Terminal) and paste the Claude Code line. Sign in when it asks.Download Node.js (LTS) from nodejs.org and install it. Then open PowerShell (Start → type PowerShell) and paste the Claude Code line. Sign in when it asks.
curl -fsSL https://claude.ai/install.sh | bash
irm https://claude.ai/install.ps1 | iex
Tip: Already have both? Skip to step 2.
Add the security-audit skill
Paste this in the same window. It installs the skill once for all your projects.
npx skills add https://github.com/cloudflare/security-audit-skill --skill security-audit --global
Open your app's folder in Claude Code
Replace the path with your project folder (tip: type cd with a space, then drag the folder onto the window).
cd ~/path/to/your-app claude
cd C:\path\to\your-app claude
Ask for the audit
Type this in Claude Code. It works through your app in six phases, so a big app can take a while. The report is saved in a folder called security-audit-skill in your home folder unless you name another place.
security audit this codebase
Fix the real problems
Open REPORT.md. Start with anything confirmed as critical or high. Ask Claude Code: "Fix finding 1 and explain what you changed." Test your app after each fix. Running the audit again finds more: Cloudflare says one run found about half of what repeated runs found.
The catch
- It reads your code. It doesn't attack your live website, and it won't run your app's code unless you've set up a locked-down sandbox.
- It's not a replacement for a real security expert on anything big, like apps handling payments or health data.
- You need Claude Code, which needs a paid Claude plan.
- Only check your own apps (or ones you have permission to check).
Stuck?
"npx: command not found"
My app is on Lovable / Bolt / Replit, not my computer
Windows: "running scripts is disabled"
Set-ExecutionPolicy -Scope CurrentUser RemoteSigned -Force once in PowerShell, then try again.Official links
Want help with this?
I show a new AI tool every week and how to make money or save hours with it. No tech background needed.
Unnerd AI · I'm not linked to Cloudflare's security-audit skill, I just think it's useful.