{"id":23977,"plugin_id":"plugins_6ab3634387ec81919729f26fb2a8e67b","kind":"skill","collection_source":null,"comparison_source":null,"observed_at":"2026-09-30T23:17:51.520Z","digest":"b3c4b95274d7ae9c48bbb9128339add84582ee8a3db27ad8496f178eb7e21963","against":null,"payload":{"name":"storage-and-binding-security","description":"Assess R2, KV, Durable Objects, Queues, Vectorize, and other Cloudflare storage or data bindings.","included_files":[],"skill_md_contents":"---\nname: storage-and-binding-security\ndescription: Assess R2, KV, Durable Objects, Queues, Vectorize, and other Cloudflare storage or data bindings.\n---\n\n# Storage and Binding Security\n\nInventory relevant resource bindings and identify which Worker can read, write, list, delete, or publish data. Review authorization before access, tenant/key namespace separation, validation of object names and uploads, content-type and size controls, malware/content handling, retention/deletion, backup/recovery, and sensitive metadata.\n\nFor R2, check public access domains, `r2.dev` exposure, custom-domain protections, CORS origin/method/header scope, presigned URL operation/object/expiry, and credential separation. Public buckets expose objects to the internet; CORS does not make a bucket private. Treat presigned URLs as bearer secrets and do not log or repeat them. For KV, assess assumptions about consistency and stale authorization state. For Durable Objects, review identity-to-object routing and per-object authorization. For Queues and async workflows, validate producer trust, message schemas, retries, idempotency, poison-message handling, and sensitive payload logging. Do not inspect object/table contents by default.\n"},"changes":[],"summary":"First saved snapshot. No earlier version is available for comparison.","summary_kind":"deterministic","summary_metadata":{}}