← Cloudflare SecurityCONTENT HISTORY

Update to Cloudflare Security

Snapshot Sep 30, 2026 · 23:17 UTC · version 0.1.0

Collection source: not recorded for this historical snapshot.

WHAT CHANGED · RULE-BASED ANALYSIS

First saved snapshot

No earlier snapshot is available to establish a change.

Compare saved observations

Download comparison JSON
Full technical diff · 0 changed fields
Full snapshot data
{
  "name": "storage-and-binding-security",
  "description": "Assess R2, KV, Durable Objects, Queues, Vectorize, and other Cloudflare storage or data bindings.",
  "included_files": [],
  "skill_md_contents": "---\nname: storage-and-binding-security\ndescription: Assess R2, KV, Durable Objects, Queues, Vectorize, and other Cloudflare storage or data bindings.\n---\n\n# Storage and Binding Security\n\nInventory relevant resource bindings and identify which Worker can read, write, list, delete, or publish data. Review authorization before access, tenant/key namespace separation, validation of object names and uploads, content-type and size controls, malware/content handling, retention/deletion, backup/recovery, and sensitive metadata.\n\nFor R2, check public access domains, `r2.dev` exposure, custom-domain protections, CORS origin/method/header scope, presigned URL operation/object/expiry, and credential separation. Public buckets expose objects to the internet; CORS does not make a bucket private. Treat presigned URLs as bearer secrets and do not log or repeat them. For KV, assess assumptions about consistency and stale authorization state. For Durable Objects, review identity-to-object routing and per-object authorization. For Queues and async workflows, validate producer trust, message schemas, retries, idempotency, poison-message handling, and sensitive payload logging. Do not inspect object/table contents by default.\n"
}

SHA-256: b3c4b95274d7ae9c48bbb9128339add84582ee8a3db27ad8496f178eb7e21963