← Files Cloudflare SecurityARCHIVED FILE
SKILL.md
1.11 KB · Sep 30, 2026 · 23:17 UTC
--- name: findings-remediation description: Produce prioritized, evidence-backed security findings, remediation plans, and verification checks. --- # Findings, Remediation, and Retesting Write concise but actionable findings with: ID/title, severity, confidence, affected resource, evidence/source/time, attack preconditions, impact, recommended fix, operational side effects, and verification/rollback. Prioritize exploitable exposure and identity/data-boundary failures before defense-in-depth gaps. Do not inflate severity or equate a missing best practice with a confirmed vulnerability. For each fix, specify whether it is code, Cloudflare configuration, identity, CI/CD, or process work. Give a staged implementation order and tests that demonstrate the control. Retest the original condition, include regression cases (unauthenticated, wrong tenant/object, expired token, malformed input, preview route, cache cross-user), and record residual risk. Clearly state checks not performed and what evidence would close each gap. Never represent partial audit coverage as certification, compliance attestation, or “100% secure.”
SHA-256: cf23c276c6467967225576010a3e42d8f3174e2a54786504e88963362d26f943