Agent skill

Cloudflare One

by hodgef in hodgef/apiker

Guides Cloudflare One Zero Trust and SASE work across Access, Gateway, WARP, Tunnel, Cloudflare WAN, DLP, CASB, device posture, and identity.

MITAuto-check passedBackend & APIs

Install Cloudflare One

skills CLI
$ npx skills add hodgef/apiker --skill cloudflare-one -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install hodgef/apiker cloudflare-one --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/hodgef/apiker.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/cloudflare-one .claude/skills/cloudflare-one && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cloudflare-one
GitHub stars
127
Used in
2 other repos
Token cost
~5.6k tokens
SKILL.md length
2,433 words
Files
1
Skills in repo
11
Repo updated
First seen
Licence
MIT

At a glance

Guides Cloudflare One Zero Trust and SASE work across Access, Gateway, WARP, Tunnel, Cloudflare WAN, DLP, CASB, device posture, and identity.

  • Works in 5 steps: Classify the ask: architecture,… → Gather context: account ID,… → Retrieve only the current docs needed… → …
  • Troubleshooting
  • SKILL.md covers Workflow, Assessment Prompts, Guardrails and Output Defaults, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Cloudflare One is an agent skill from hodgef/apiker. Guides Cloudflare One Zero Trust and SASE work across Access, Gateway, WARP, Tunnel, Cloudflare WAN, DLP, CASB, device posture, and identity. Use when designing, configuring, troubleshooting, or reviewing Cloudflare One deployments. Retrieval-first: use current Cloudflare docs/API schemas instead of embedded product docs.

Its SKILL.md is about 5.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Deployment and OpenAPI specifications. It works with Cloudflare and Cloudflare Workers. The repository describes itself as: 🔼 Create Serverless APIs with Cloudflare Workers, Durable Objects & Wrangler. The licence is MIT.

When your agent uses it

  • Troubleshooting
  • Reviewing Cloudflare One deployments

Example prompts

  • “Use the cloudflare-one skill to guide Cloudflare One Zero Trust and SASE work across Access, Gateway, WARP, Tunnel, Cloudflare WAN, DLP, CASB…”
  • “/cloudflare-one”

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Classify the ask: architecture, configuration, troubleshooting, migration, or review.
  2. Gather context: account ID, users/sites/apps, identity provider, SCIM/group sync, device management, traffic path, compliance constraints…
  3. Retrieve only the current docs needed for the products involved: Access, Gateway, WARP/device client, Tunnel/Mesh, Cloudflare WAN, DLP…
  4. If account access is available, inspect existing resources before proposing or making changes: Access apps/policies/groups/IdPs, Gateway…
  5. Propose the change set with prerequisites, validation, and rollback. For risky changes, stage disabled or scoped to a pilot group/site…

What it can do on your machine

Read from SKILL.md and the folder at commit 444ace2. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • developers.cloudflare.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cloudflare One loads about 5.6k tokens when it runs. Until then it costs about 85 tokens; SKILL.md has 2,433 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~85
When it runs · the whole SKILL.md, loaded when a task matches
~5.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from hodgef/apiker at commit 444ace2, republished under its MIT licence (© hodgef). 2,433 words, ~5,574 tokens.

Download SKILL.mdSave it as .claude/skills/cloudflare-one/SKILL.md (or your agent's skills folder).
name
cloudflare-one
description
Guides Cloudflare One Zero Trust and SASE work across Access, Gateway, WARP, Tunnel, Cloudflare WAN, DLP, CASB, device posture, and identity. Use when designing, configuring, troubleshooting, or reviewing Cloudflare One deployments. Retrieval-first: use current Cloudflare docs/API schemas instead of embedded product docs.

Cloudflare One

Before citing limits, settings, API fields, category IDs, or exact UI paths, retrieve current information from the Cloudflare One docs, the Cloudflare docs MCP server, or the Cloudflare API schema.

Workflow

  1. Classify the ask: architecture, configuration, troubleshooting, migration, or review.
  2. Gather context: account ID, users/sites/apps, identity provider, SCIM/group sync, device management, traffic path, compliance constraints, and rollout blast radius.
  3. Retrieve only the current docs needed for the products involved: Access, Gateway, WARP/device client, Tunnel/Mesh, Cloudflare WAN, DLP, CASB, device posture, or identity.
  4. If account access is available, inspect existing resources before proposing or making changes: Access apps/policies/groups/IdPs, Gateway rules/lists/categories, device profiles/posture checks, tunnels/routes, DNS/resolver settings, and locations/sites.
  5. Propose the change set with prerequisites, validation, and rollback. For risky changes, stage disabled or scoped to a pilot group/site unless the user explicitly asks otherwise.

Assessment Prompts

Use these to avoid jumping straight to configuration. Ask only the prompts relevant to the user's task.

Architecture and Current State
  • Sites and users: offices, branches, data centers, VPCs, remote users, contractors, user counts, and current connectivity model.
  • Applications and destinations: SaaS, public apps, private apps, APIs, infrastructure targets, protocols, ports, hostnames, and IP ranges.
  • Connectivity: VPN, MPLS, SD-WAN, direct Internet breakout, centralized backhaul, site-to-site needs, and private DNS architecture.
  • Security stack: current SWG, NGFW, VPN/ZTNA, DLP, CASB, email security, logging, and compliance requirements.
  • Identity: IdP, SCIM/group sync, group naming, multi-IdP needs, service accounts, and contractor/partner access.
  • Rollout: pilot users/sites, blast radius, rollback path, support owners, and success criteria.
Access and SaaS Federation
  • App shape: web app, API, SSH/RDP/VNC, database, SaaS app, public hostname, private IP, or private hostname. Retrieve Access application type docs before choosing.
  • Access model: clientless browser access, private networking with device client, peer to peer connectivity, service connections with service tokens or mutual TLS, or SaaS SSO federation.
  • Policy needs: user groups, device posture, session duration, mTLS, service tokens, and app launcher visibility. Retrieve Access policy docs before configuring selectors or evaluation order.
  • SaaS details: SAML vs OIDC support, ACS/redirect URLs, Entity IDs/client IDs, required attributes, and tenant-control requirements.
Tunnel and Private Networking
  • Sites and segments: which data centers, VPCs, offices, or network segments need connectivity.
  • HA: dev/test single connector, production multiple connectors, or advanced multi-tunnel/site redundancy.
  • Runtime: where cloudflared or WARP Connector/Mesh will run: VM, container, Kubernetes, bare metal, or other target.
  • Egress: whether connectors can reach Cloudflare over the required outbound ports/protocols. Retrieve Tunnel connectivity prechecks before naming exact endpoints.
  • Origin reachability: whether the connector can resolve and reach every private origin.
  • Routing: required CIDRs/hostnames, overlapping IP spaces, virtual networks, Split Tunnels, and private DNS/resolver policy needs.
  • Management model: prefer remotely managed/token-based tunnels for new deployments unless there is a clear reason for local config.
Gateway, TLS, and DLP
  • Traffic controls: DNS categories, HTTP URL/path inspection, L4 ports/protocols, egress IP requirements, custom lists, and allow/block exceptions. Retrieve Gateway traffic policy docs for current selectors and order of enforcement.
  • Identity: whether Gateway policies need user or group selectors, and whether users will be authenticated through WARP/IdP context. Check Gateway identity selectors and SCIM provisioning when groups are involved.
  • TLS inspection: root CA deployment path, certificate-pinned applications, compliance exceptions, and FIPS requirements. Retrieve TLS decryption docs before enabling.
  • DLP: sensitive data types, channels to inspect, TLS inspection readiness, DLP profiles, payload logging requirements, and false-positive tolerance. Retrieve DLP docs before creating enforcement.
CASB, Device Posture, and Risk
  • CASB: SaaS vendors, admin access level, scan policy, org size, remediation owner, and whether inline protection is also required. Retrieve CASB findings docs before recommending remediation.
  • Device posture: required checks, third-party EDR/MDM integrations, enrollment rules, device profiles, and split tunnel alignment.
  • Risk scoring: relevant behavior signals, false-positive sources such as VPNs or service accounts, and whether risk is for investigation or enforcement. Retrieve user risk score docs before using risk in policies.
Cloudflare WAN / Site Connectivity
  • Site topology, on-ramp type, route ownership, tunnel redundancy, static vs BGP-managed routes, network firewall needs, and appliance/profile ownership. Retrieve Cloudflare WAN and Cloudflare Network Firewall docs before proposing site connectivity changes.

Guardrails

  • Access controls application authorization; Gateway controls traffic inspection/filtering. Use both when the requirement spans identity-aware app access and network/web security.
  • Public hostname Access apps can be clientless. Private destination apps require WARP/Device client or another network on-ramp plus routes and DNS resolution. Retrieve self-hosted private app docs before configuring private destinations.
  • Cloudflare Tunnel is an off-ramp from a private network to Cloudflare. Cloudflare WAN and Mesh are other off-ramps which can also be on-ramps.
  • Group-based policies depend on IdP group claims or SCIM. If group sync is missing, do not invent group selectors.
  • Private hostnames need explicit DNS routing/resolution; creating an Access app alone is not enough. Use resolver policies and review Connect a private hostname
  • HTTP inspection and DLP for encrypted web traffic require TLS inspection and planned Do Not Inspect exceptions.
  • Gateway DNS, Network, HTTP, and Egress policies have different evaluation semantics. Retrieve order of enforcement docs before explaining precedence.
  • Start broad block/allow/DLP/TLS policies disabled limited to a pilot with specific target users or groups unless the user approves a wider rollout.
Identity and Access
  • Access Groups are Cloudflare objects; IdP/SCIM groups are identity claims. Gateway group selectors use synced IdP groups, not Access Groups.
  • Group names and SAML/OIDC attributes are case-sensitive. Verify exact claim names and values before creating group-based rules.
  • SCIM changes and group membership can be stale until sync and re-authentication complete. Troubleshoot with the user's last authenticated identity, not just the IdP state.
  • Access policies are default-deny. A private app with routes but no Allow policy still blocks access.
  • Access policy selectors can use IP lists, not Gateway domain or URL lists.
  • SaaS federation handles authentication into the SaaS app. SaaS authorization and tenant restrictions usually require SaaS-side roles and/or Gateway tenant controls.
  • Browser Rendering for SSH/VNC/RDP is an Access capability. Browser Isolation renders general web content remotely. Do not conflate them.
Device Client Deployment
  • The Cloudflare One device client is the on-ramp for user devices. Two components control it: enrollment rules (who can connect) and device profiles (how the client behaves after enrollment).

  • The enrollment rule is an Access application of type warp, not a device setting. It accepts reusable Access policies. Look in Access for enrollment debugging, not Devices.

  • For headless or autonomous devices (services, kiosks, Linux hosts), use service token enrollment. Non-human devices authenticate as non_identity@[team-domain].cloudflareaccess.com and have no group membership - device profiles targeting IdP groups will not match them. Target headless devices explicitly with the non-identity email, specific conventions about the devices (OS information, etc.),or let them fall to the default profile.

  • Device profiles control connection mode, split tunnel configuration, user permissions (disable, switch lock), auto-reconnect, and captive portal behavior. Profiles are matched by user group or device attributes in precedence order - first match wins, default profile catches the rest.

  • Split tunnel mode is the single most impactful client setting. Choose the mode based on the deployment goal:

    GoalModeRationale
    VPN replacement only (private apps)IncludeRoute only specified private CIDRs and hostnames through the client. Everything else goes direct. Minimal blast radius.
    SWG only (internet security)ExcludeAll traffic through the client. Exclude only what breaks (local printers, certificate-pinned apps).
    VPN replacement + SWGExcludeAll traffic through the client. Most common enterprise configuration.
    Coexistence with another VPNIncludeAvoids conflict with the other VPN's tunnel interface and DNS control.
    DNS filtering onlyDNS-only modeOnly DNS queries go to Gateway. No traffic proxying.
  • Include vs exclude is per-profile, not per-entry. You cannot mix modes in the same profile. Switching modes mid-deployment requires re-evaluating every entry.

  • Split tunnel entries must align with tunnel routes bidirectionally. A CIDR in the include list without a matching tunnel route causes a black hole. A tunnel route without a matching device profile entry means traffic never enters the tunnel.

  • MDM parameters (mdm.xml / managed preferences) override dashboard-configured profile settings for any setting specified in the file. If dashboard changes appear to have no effect on managed devices, check MDM config. Retrieve MDM deployment docs for platform-specific file locations and parameters.

  • If another VPN client or agent controls DNS on the device, the device client's DNS interception will conflict. In coexistence scenarios, use "traffic only" mode to avoid routing table and DNS conflicts.

  • Captive portal detection temporarily disconnects the client when it detects a portal (hotel WiFi, airport). This is a common source of end-user friction and should be managed carefully.

Show full SKILL.md (1,036 more words)Show less
Private Networking
  • Split tunnel mode changes the meaning of every route decision: Exclude mode sends traffic to Cloudflare when removed from excludes; Include mode sends traffic only when added to includes.
  • Virtual networks should be used primarily when IP subnets overlap and hostname-based routing is not used. It can be used to control other user connectivity behavior, but it is recommended to manage through security policies.
  • A healthy tunnel only proves cloudflared can reach Cloudflare. The tunnel must have appropriate published application routes, network routes, or hostname routes for connectivity to function.
  • Cloudflare Tunnel and Cloudflare Mesh can both be used to facilitate connectivity to internal networks. Cloudflare WAN can as well, but it is gated behind Enterprise subscriptions. Retrieve choose an on-ramp when deliberating between Tunnel types.
  • Run multiple cloudflared connectors for production HA, preferably on separate hosts. Token-based, remotely managed tunnels are the default for new deployments.
Gateway, TLS, and DLP
  • dns.domains matches a domain and subdomains; dns.fqdn is exact-match only.
  • DNS pre-resolution selectors and post-resolution selectors do not behave like a single strict precedence list. Retrieve current evaluation docs before changing rule order.
  • HTTP Do Not Inspect rules run before HTTP Allow/Block/Isolate behavior. A later block rule will not override an earlier inspection bypass.
  • Certificate-pinned apps need Do Not Inspect exceptions before broad TLS inspection. Deploy the Cloudflare root CA to managed devices before enabling inspection.
  • DLP profiles are detection definitions only. They do nothing until referenced by Gateway HTTP policies or CASB scan settings. Rules with body inspection may be evaluated multiple times in a single pass.
  • Start DLP with payload logging where appropriate, tune false positives, then block.
  • Gateway Network policies are strict L4 controls. Identity-aware L4 matching requires authenticated device context.
CASB, Risk, and Operations
  • API CASB is out-of-band and periodic. It does not provide real-time inline enforcement although some integrations support "remediation"; use Gateway granular application controls for inline CASB capability for supported applications. Retrieve Granular application controls when creating security policies for specific actions in specific SaaS applications.
  • CASB findings are tied to specific assets and instances. Drill into affected assets before recommending remediation.
  • Use current Dashboard remediation guidance for CASB fixes. Most remediations happen in the SaaS admin console, not Cloudflare.
  • Large SaaS integrations can take 24-48 hours for initial scans. Reauthorizing can restart scan state; check credential health before reconnecting.
  • User risk scores are behavior-based and asynchronous. CASB findings do not automatically imply high user risk.
Infrastructure Access
  • Zero Trust Infrastructure Access (ZTIA) is the purpose-built offering for SSH access through the device client. It provides capabilities not available through self-hosted apps: keystroke logging, control over how users authenticate to the target machine, short-lived certificates that replace static SSH keys with ephemeral certs tied to Access identity, and lightweight privileged access management. Use Infrastructure Access apps for SSH when the device client is deployed.
  • Browser Rendering provides clientless SSH, RDP, and VNC through the browser without requiring the device client. Clientless RDP includes session recording and file transfer controls. Use clientless access when a device client cannot be installed (contractors, partner access, unmanaged devices) - typically not as the default for managed users with the client installed.
  • Audit SSH is a Gateway Network policy action that logs SSH commands without blocking. It requires the session to be proxied through Cloudflare.
  • Short-lived certificates require CA configuration on the target host and sshd configured to trust the Cloudflare CA public key. Retrieve short-lived certificate setup docs before configuring.
  • For kubectl and database access behind private networks, use the device client with private destination routing. There is no Infrastructure Access or browser-rendered equivalent for arbitrary TCP protocols today.
Logs, Analytics, and DEX
  • Gateway activity logs record DNS, HTTP, and Network policy decisions. Filter by rule name, user identity, destination, action, and time range. These are the primary troubleshooting tool for "why was this blocked/allowed."
  • Access audit logs record authentication decisions per app - who authenticated, which policy matched, and session details. Use for verifying policy behavior and investigating access failures.
  • Shadow IT discovery uses Gateway HTTP logs to surface unmanaged SaaS applications. Requires TLS inspection for HTTPS visibility.
  • DEX (Digital Experience Monitoring) provides fleet-level and per-device connectivity diagnostics. Use DEX tests (HTTP, traceroute) to proactively monitor reachability to critical origins and internal apps. Fleet status shows device client health, connection mode, and connectivity state across the enrolled population.
  • Logpush exports Gateway, Access, Network, and DEX logs to external SIEM or storage. Configure before go-live if the customer requires centralized log retention or compliance reporting.
  • When troubleshooting, work from logs toward config: identify the log entry showing the failure (Gateway block, Access deny, tunnel error, DNS resolution miss), then trace back to the responsible rule, route, or policy.
Cloudflare WAN / Site Connectivity
  • Cloudflare WAN is connectivity, not a security service. Apply inspection and policy with Gateway and Network Firewall where required.
  • WAN firewall expressions are not the same language as Gateway wirefilter expressions. Retrieve the current syntax before editing.
  • Generated IPsec PSKs and some OAuth/client secrets are returned once. Store them immediately.

Output Defaults

  • Designs: current assumptions, target architecture, product responsibilities, rollout phases, validation, and open decisions.
  • Configuration work: prerequisites, exact resources to inspect/create/change, test cases, and rollback.
  • Troubleshooting: traffic path, likely failure point, evidence to collect, and next test.

Validation Prompts

  • Access: test authorized, unauthorized, posture-failing, service-token, and multi-IdP flows when applicable; inspect logs and policy precedence.
  • Private network access: verify route lookup, tunnel health, origin reachability, split tunnel behavior, DNS resolution, and end-to-end access from a device client test device.
  • Gateway: verify rule type, action, traffic expression, precedence/evaluation phase, referenced lists, and Gateway settings before enabling broadly.
  • TLS/DLP: test Do Not Inspect exceptions and root CA trust before enabling inspection; test DLP with known samples and monitor false positives before blocking.
  • CASB/risk: confirm integration health, credential expiry, asset discovery, scan timing, finding instances, and risk-score signal latency before declaring remediation complete.
  • Cloudflare WAN: verify tunnel health, route priority/ownership, traffic flow, firewall expression syntax, and connector/appliance telemetry where applicable.

API Safety

  • Use fully qualified MCP tool names when MCP tools are available.
  • Never guess category IDs, application IDs, wirefilter fields, or API request bodies. Retrieve the current schema/docs and existing account objects.
  • Do not enable broad production policies without explicit approval.

© hodgef, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/cloudflare-one of hodgef/apiker.

Open the folder on GitHubat commit 444ace2

Used in 2 other repositories

We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in hodgef/apiker, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Cloudflare One next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cloudflare One compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cloudflare One this skillhodgef/apiker1272 repos~5.6kAutomated safety check: PassMIT
Nextjs On Cloudflarecloudflare/skills3k2 repos~678Automated safety check: PassApache-2.0
Prepare Cloudflare Production DeploymentLubomirGeorgiev/cloudflare-workers-nextjs-saas-template786—~5.9kAutomated safety check: NotesMIT
Deploy Microfeedmicrofeed/microfeed4.1k—~6.6kAutomated safety check: PassAGPL-3.0
Wranglercloudflare/skills3k2 repos~2.8kAutomated safety check: PassApache-2.0
Cloudflare Temporary DeployLuciole-Studio/Misaka-Agent1392 repos~1.9kAutomated safety check: PassMIT

Similar skills

  • Nextjs On Cloudflare

    cloudflare/skills

    Official

    Build, migrate, and deploy Next.js apps on Cloudflare Workers with vinext.

    3k GitHub starsUsed in 2 repos~678 tokens
    DevOps & CloudAuto-check passed
  • Prepare Cloudflare Production Deployment

    LubomirGeorgiev/cloudflare-workers-nextjs-saas-template

    Source-of-truth runbook for preparing this Vinext Cloudflare Workers SaaS template for production deployment.

    786 GitHub stars~5.9k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Deploy Microfeed

    microfeed/microfeed

    Deploy and administer microfeed through the source-code-free @microfeed/cli launcher or the project-owned yarn manage CLI.

    4.1k GitHub stars~6.6k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Wrangler

    cloudflare/skills

    Official

    Run or troubleshoot Wrangler CLI commands and configure Worker projects for local development, Previews, deployment, and Cloudflare resource management.

    3k GitHub starsUsed in 2 repos~2.8k tokens
    DevOps & CloudAuto-check passed
  • Cloudflare Temporary Deploy

    Luciole-Studio/Misaka-Agent

    Deploy a Worker live, no account, via wrangler --temporary. An agent skill from Luciole-Studio/Misaka-Agent.

    139 GitHub starsUsed in 2 repos~1.9k tokens
    DevOps & CloudAuto-check passed
  • Cloudflare Deploy

    JetBrains/skills

    Official

    Deploy applications and infrastructure to Cloudflare using Workers, Pages, and related platform services.

    364 GitHub starsUsed in 6 repos~1.8k tokens
    DevOps & CloudAuto-check passed

More from hodgef/apiker

All 11 skills in this repo
  • Cloudflare

    hodgef/apiker

    Comprehensive Cloudflare platform skill covering Workers, Pages, storage (KV, D1, R2), AI (Workers AI, Vectorize, Agents SDK), feature flags (Flagship), networking (Tunnel, Spectrum), security (WAF…

    127 GitHub starsUsed in 7 repos~2.2k tokens
    Auto-check passed
  • Durable Objects

    hodgef/apiker

    Create and review Cloudflare Durable Objects. An agent skill from hodgef/apiker.

    127 GitHub starsUsed in 4 repos~1.5k tokens
    Auto-check passed
  • Send and receive transactional emails with Cloudflare Email Service (Email Sending + Email Routing).

    127 GitHub starsUsed in 3 repos~2k tokens
    Auto-check passed
  • Web Perf

    hodgef/apiker

    Analyzes web performance using Chrome DevTools MCP. An agent skill from hodgef/apiker.

    127 GitHub starsUsed in 5 repos~2k tokens
    Auto-check passed
  • Reviews and authors Cloudflare Workers code against production best practices.

    127 GitHub starsUsed in 6 repos~1.8k tokens
    Auto-check passed
  • Apiker

    hodgef/apiker

    Develop, review, and extend the Apiker library — a framework for building serverless REST APIs on Cloudflare Workers + Durable Objects.

    127 GitHub stars~1.4k tokensUpdated 1 mo ago
    Auto-check passed

Questions about Cloudflare One

What does Cloudflare One do?

Guides Cloudflare One Zero Trust and SASE work across Access, Gateway, WARP, Tunnel, Cloudflare WAN, DLP, CASB, device posture, and identity. Cloudflare One is an agent skill from hodgef/apiker. Guides Cloudflare One Zero Trust and SASE work across Access, Gateway, WARP, Tunnel, Cloudflare WAN, DLP, CASB, device posture, and identity.

When should I use Cloudflare One?

Cloudflare One fits situations like: troubleshooting; reviewing Cloudflare One deployments.

How do I install Cloudflare One in Claude Code?

Run `npx skills add hodgef/apiker --skill cloudflare-one -a claude-code`. Or copy the skill folder (.agents/skills/cloudflare-one in hodgef/apiker) into .claude/skills/cloudflare-one in your project. Claude Code loads it when a task matches its description.

How do I install Cloudflare One in Codex?

Run `npx skills add hodgef/apiker --skill cloudflare-one -a codex`. Or copy the skill folder (.agents/skills/cloudflare-one in hodgef/apiker) into .agents/skills/cloudflare-one in your project. Codex loads it when a task matches its description.

Can I use Cloudflare One in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add hodgef/apiker --skill cloudflare-one -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cloudflare-one, .gemini/skills/cloudflare-one, .github/skills/cloudflare-one and .opencode/skills/cloudflare-one in your project.

What does Cloudflare One need to run?

SKILL.md names no scripts, command-line tools or credentials: Cloudflare One is instructions for the agent only.

Does Cloudflare One access the network?

SKILL.md names 1 domain. As links in the text: developers.cloudflare.com. This is read from the text; nothing was executed.

Is Cloudflare One safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Cloudflare One use?

Cloudflare One is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cloudflare One use?

About 5.6k tokens (SKILL.md is roughly 22k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Cloudflare One?

Skills that share tags, products or a category with Cloudflare One: Nextjs On Cloudflare (cloudflare/skills, 3k stars), Prepare Cloudflare Production Deployment (LubomirGeorgiev/cloudflare-workers-nextjs-saas-template, 786 stars), Deploy Microfeed (microfeed/microfeed, 4.1k stars) and Wrangler (cloudflare/skills, 3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cloudflare One?

hodgef (a GitHub user) maintains it in hodgef/apiker, which has 127 GitHub stars. The repository holds 11 skills in this directory. The repository was last updated on August 20, 2026.

Source: hodgef/apiker on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.