{"id":23979,"plugin_id":"plugins_6ab3634387ec81919729f26fb2a8e67b","kind":"skill","collection_source":null,"comparison_source":null,"observed_at":"2026-09-30T23:17:51.545Z","digest":"5c24fa324f6ccbc8306ca7b606bc2789163a7458e921e0660c15d0868e9958fa","against":null,"payload":{"name":"waf-api-abuse-protection","description":"Review Cloudflare WAF, API Shield, bot controls, endpoint exposure, and abuse/rate-limit defenses.","included_files":[],"skill_md_contents":"---\nname: waf-api-abuse-protection\ndescription: Review Cloudflare WAF, API Shield, bot controls, endpoint exposure, and abuse/rate-limit defenses.\n---\n\n# WAF, API, and Abuse Protection\n\nInventory public endpoints and classify by authentication, sensitivity, and business impact. Review managed/custom WAF rules, exposed credential detection if entitled, API inventory/schema validation, JWT validation, mTLS, rate limiting, bot controls, GraphQL protections, and relevant logs. Map controls to actual routes and methods; a WAF rule does not repair broken object authorization or unsafe application logic.\n\nCheck plan/entitlement availability before recommending a feature. Tune limits per endpoint and identity/session where possible; broad IP-only limits can affect shared NAT users and may not stop distributed abuse. Cloudflare rate limiting can have detection/enforcement delay, so do not promise exact origin request ceilings. Recommend log/challenge observation and false-positive review before blocking. Do not create, enable, or reorder rules without explicit approval, validated expressions, change window, and rollback steps.\n"},"changes":[],"summary":"First saved snapshot. No earlier version is available for comparison.","summary_kind":"deterministic","summary_metadata":{}}