Score breakdown
Popularity is tracked separately. Support, ads, sponsorships, and tips never affect these signals.
Why it matters
Useful for security-conscious teams that want agent-assisted audits to do more than dump a first-pass vulnerability list, especially when they need a repeatable process that tries to kill false positives before reporting them.
Who should use it
Who should skip it
Move on from cloudflare/security-audit-skill if the licensing terms, language support, or platform requirements do not fit your project.
About this signal
cloudflare/security-audit-skill is tracked by RepoRadar as a developer tool in the Radar section. First seen 2026-06-19; the source record was last checked on 2026-06-19. The current verdict is 'watch' with a Gold tier and advanced setup difficulty. cloudflare/security-audit-skill leads on workflow potential (9.2) and open-source/build quality (8.4); its lowest signal is setup ease (4.2), so factor that in before investing setup time. This page summarizes the public evidence on the linked source page and states where additional review is still needed.
How this item is evaluated
The cloudflare/security-audit-skill record combines a 8.4/10 composite score with separate popularity (54.0), risk (conditional), and setup (advanced) signals. See the scoring methodology for the current weights and evidence definitions.
Putting this into practice? Read How to vet an AI agent or MCP server before you wire it in for the checklist behind this score.
Risk explanation
This skill coordinates multiple agents against real source code and writes detailed findings artifacts, so keep runs scoped to repositories and environments you control before using it on sensitive private code.