← Cloudflare SecurityCONTENT HISTORY

Update to Cloudflare Security

Snapshot Sep 30, 2026 · 23:17 UTC · version 0.1.0

Collection source: not recorded for this historical snapshot.

WHAT CHANGED · RULE-BASED ANALYSIS

First saved snapshot

No earlier snapshot is available to establish a change.

Compare saved observations

Download comparison JSON
Full technical diff · 0 changed fields
Full snapshot data
{
  "name": "dns-tls-origin-security",
  "description": "Review Cloudflare DNS, DNSSEC, TLS, certificates, origin exposure, and tunnel configuration.",
  "included_files": [],
  "skill_md_contents": "---\nname: dns-tls-origin-security\ndescription: Review Cloudflare DNS, DNSSEC, TLS, certificates, origin exposure, and tunnel configuration.\n---\n\n# DNS, TLS, and Origin Security\n\nReview authoritative DNS and record exposure, DNSSEC status and registrar DS coordination, TLS mode, certificate validity/hostname coverage, HTTPS redirects, origin TLS, Authenticated Origin Pulls where relevant, and whether direct origin access can bypass Cloudflare controls. Recommend Full (strict) only after confirming the origin certificate and HTTPS path are valid; warn about 526/outage risks and test before enforcing. Check for leaked historical origin addresses and non-proxied records only as evidence permits.\n\nConsider Cloudflare Tunnel for suitable origins to avoid public inbound origin reachability, paired with restrictive egress/firewall policy and protected tunnel credentials. Tunnel does not replace application authentication or Access policy. Never change nameservers, DNSSEC, DNS records, TLS mode, or firewall state during audit. Require an explicit, specific approval and staged rollback plan before any such mutation.\n"
}

SHA-256: 8b21d99d939ed6f09074be67fc445d8026945c810c333517a8588902997396ac