← Cloudflare SecurityCONTENT HISTORYWHAT CHANGED · RULE-BASED ANALYSIS
Update to Cloudflare Security
Snapshot Sep 30, 2026 · 23:17 UTC · version 0.1.0
Collection source: not recorded for this historical snapshot.
First saved snapshot
No earlier snapshot is available to establish a change.
Compare saved observations
Download comparison JSONFull technical diff · 0 changed fields
Full snapshot data
{
"name": "dns-tls-origin-security",
"description": "Review Cloudflare DNS, DNSSEC, TLS, certificates, origin exposure, and tunnel configuration.",
"included_files": [],
"skill_md_contents": "---\nname: dns-tls-origin-security\ndescription: Review Cloudflare DNS, DNSSEC, TLS, certificates, origin exposure, and tunnel configuration.\n---\n\n# DNS, TLS, and Origin Security\n\nReview authoritative DNS and record exposure, DNSSEC status and registrar DS coordination, TLS mode, certificate validity/hostname coverage, HTTPS redirects, origin TLS, Authenticated Origin Pulls where relevant, and whether direct origin access can bypass Cloudflare controls. Recommend Full (strict) only after confirming the origin certificate and HTTPS path are valid; warn about 526/outage risks and test before enforcing. Check for leaked historical origin addresses and non-proxied records only as evidence permits.\n\nConsider Cloudflare Tunnel for suitable origins to avoid public inbound origin reachability, paired with restrictive egress/firewall policy and protected tunnel credentials. Tunnel does not replace application authentication or Access policy. Never change nameservers, DNSSEC, DNS records, TLS mode, or firewall state during audit. Require an explicit, specific approval and staged rollback plan before any such mutation.\n"
}SHA-256: 8b21d99d939ed6f09074be67fc445d8026945c810c333517a8588902997396ac