← Cloudflare SecurityCONTENT HISTORY

Update to Cloudflare Security

Snapshot Sep 30, 2026 · 23:17 UTC · version 0.1.0

Collection source: not recorded for this historical snapshot.

WHAT CHANGED · RULE-BASED ANALYSIS

First saved snapshot

No earlier snapshot is available to establish a change.

Compare saved observations

Download comparison JSON
Full technical diff · 0 changed fields
Full snapshot data
{
  "name": "workers-pages-security",
  "description": "Review Cloudflare Workers and Pages code, bindings, routes, previews, and application security boundaries.",
  "included_files": [],
  "skill_md_contents": "---\nname: workers-pages-security\ndescription: Review Cloudflare Workers and Pages code, bindings, routes, previews, and application security boundaries.\n---\n\n# Workers and Pages Security\n\nInspect Worker/Pages source, Wrangler configuration, routes, bindings, environment separation, preview deployments, and request/response handling. Trace authentication before sensitive operations and enforce authorization at every object, tenant, and function boundary. Validate and bound untrusted input; assess SSRF, injection, path traversal, unsafe redirects, mass assignment, resource exhaustion, and error disclosure where applicable. Review binding capabilities as permissions and limit each Worker to the resources it needs. Prefer private service bindings for internal Worker communication when appropriate, while independently authenticating downstream operations: Access context does not automatically propagate through service bindings.\n\nCheck whether Pages previews expose non-production data or credentials; preview URLs are public by default unless protected. Review routes/custom hostnames and ensure staging is isolated. Report code-level evidence and distinguish static concerns from runtime-verified vulnerabilities. Do not deploy or modify production settings without explicit approval.\n"
}

SHA-256: efa99597a8220076d0cd85fbbbb5cdd5f1892c9b48ca8a098bdff635bc7203dd