Cloudflare Workers Security

Security audit for Cloudflare Workers applications covering bindings (KV, D1, R2, Durable Objects, Queues, Vectorize), secrets vs vars in wrangler.toml, Worker routes and zones, request origin validation, CORS, mTLS to origin, Smart Placement, and Workers-specific runtime concerns. Use this skill whenever the user mentions Cloudflare Workers, wrangler, wrangler.toml, KVNamespace, D1Database, R2Bucket, DurableObjectNamespace, Env bindings, c.env, env.MY_KV, or asks "audit my Cloudflare Worker", "Workers security review", "wrangler secrets". Trigger when the codebase contains `wrangler` or `@cloudflare/workers-types` in package.json.

hlsitechio 410779b 7.8 KB Updated

File contents

hlsitechio/claude-skills-security/tree/main/appsec-stack-pack/cloudflare-workers-security commit 410779bc61

Frequently asked questions

npx skillmds@latest add hlsitechio/cloudflare-workers-security