{"id":23862,"plugin_id":"plugins_6ab3634387ec81919729f26fb2a8e67b","kind":"skill","collection_source":null,"comparison_source":null,"observed_at":"2026-09-30T23:17:48.855Z","digest":"b2c0344adb192241340b0862cc8dc35498428daaa9a0080a620e325d898c7e66","against":null,"payload":{"name":"account-identity-hardening","description":"Review Cloudflare account access, API-token scope, Access policies, and service credentials.","included_files":[],"skill_md_contents":"---\nname: account-identity-hardening\ndescription: Review Cloudflare account access, API-token scope, Access policies, and service credentials.\n---\n\n# Account and Identity Hardening\n\nReview users, account roles, membership scope, authentication protections, session/security posture, Access applications and policies, service tokens, and API-token metadata where available. Use least-privilege recommendations: scope tokens to required account/zone resources and permissions, set appropriate expiration and IP restrictions when operationally feasible, separate automation identities, inventory stale credentials, and document rotation/revocation ownership.\n\nNever request or display token or secret values. Do not infer MFA enrollment from unrelated account metadata. Distinguish an API token's configured scope from proof of where it is used. Flag Access Bypass rules because they disable Access enforcement for matching traffic; assess whether a narrower policy or Service Auth is appropriate. Before recommending changes, consider lockout, automation outages, emergency recovery, and staged validation. Read only; credential rotation, revocation, and policy edits require explicit per-action approval.\n"},"changes":[],"summary":"First saved snapshot. No earlier version is available for comparison.","summary_kind":"deterministic","summary_metadata":{}}