cloudflare/security-audit-skill
A coding-agent skill for multi-phase security audits with independently verified, machine-readable findings
Seismograph spotted this repository 42 hours before it took off on Hacker News.
About the project
A coding-agent skill that turns the agent into a security auditor, running a multi-phase code audit with independently verified, machine-readable findings.
Useful for
- Run a security audit of a repository and get a report with confirmed vulnerabilities
- Re-run the audit to close coverage gaps from previous runs
- Verify agent findings with independent verifiers before publishing the report
README summarized by DeepSeek V4.1 Flash. Details may be inaccurate.
Why it’s trending
- 1,688 stars so far today, about 2,334 expected by the end of the day. The usual pace is 12 per day, so that's 200× as much.
- Over the last two days the pace is 16× that of the previous week and a half.
- The spike has held for 3 days in a row — not a one-off blip.
- GitHub Trending today: #1, +3,019 stars.
- GitHub Trending JavaScript today: #1, +3,019 stars.
- Hacker News: “Cloudflare/Security-Audit-Skill” — 205 points, 1 day ago.
- About 160 forks a day — people are taking the code.
Stars per day
Bars are daily stars, the line is the usual pace. Red marks spike days.
Numbers
- Total stars
- 12,885
- Stars in a day
- 2,334
- Forks
- 691
- Issues and pull requests
- 38
- Watchers
- 49
- Language
- JavaScript
- License
- MIT
- Created
- June 18, 2026
- Last push
- September 14, 2026
Star trust
Growth looks organic: forks and discussion are in line with active projects, and stars arrive unevenly, the way people give them.
These are heuristics, not a verdict: we judge by the repository’s behavior, not by a list of stargazers.
Hacker News discussions
- Cloudflare/Security-Audit-Skill205 points, September 17, 2026
Spotted in
- September 18, 2026GitHub Trending today: #1, +3,019 stars; GitHub Trending JavaScript today: #1, +3,019 stars; GitHub Trending this month: #12, +6,981 stars; Top new repositories in the last 4 months: #23; Spotted on Hacker News
- September 17, 2026GitHub Trending today: #2, +3,606 stars; GitHub Trending JavaScript today: #1, +3,606 stars; Top new repositories in the last 4 months: #30; Spotted on Hacker News
- September 16, 2026GitHub Trending today: #2, +1,249 stars; GitHub Trending JavaScript today: #1, +1,249 stars; Top new repositories in the last 4 months: #62
- September 15, 2026GitHub Trending JavaScript today: #9, +1,210 stars; Top new repositories in the last 4 months: #91
Similar projects
-
6.6
yynxxxxx/gpt_sub_analysis
A guide to analyzing the ChatGPT iOS subscription flow: it describes intercepting the buyProduct request via Reqable and SSL Kill Switch 3 and rewriting the offerName and salableAdamId fields to obtain the Pro 20x…
-
5.9
ctdal/cve-2026-41940-PoC
PoC exploit for CVE-2026-41940, a critical authentication bypass in cPanel & WHM (CVSS 10.0) that grants unauthenticated root-level WHM access by injecting CRLF sequences into server-side session files.
-
5.3
BennyThink/NFCX
Cross-platform GUI desktop app for NFC card work: reader discovery, MIFARE Classic reads, dumps, key management, and key recovery. For cards you own or are authorized to test.
-
5.0
NationalSecurityAgency/ghidra
A software reverse engineering framework from the NSA: disassembly, decompilation, graphing and scripting for analyzing compiled code on Windows, macOS and Linux.
-
4.6
shinthink/blitzstrike
A TypeScript/Bun MCP server packaging a pentest methodology into three tiers: attack-surface reconnaissance, source-to-sink tracing, and live validation of findings before reporting.
-
4.6
bl4ckarch/go-responder
A Go port of Responder: poisons LLMNR, NBT-NS and mDNS, runs rogue servers (SMB, HTTP, LDAP, etc.) and captures NTLM hashes and cleartext credentials.