Agent skill

Deploying Cloudflare Access For Zero Trust

by mukul975 in mukul975/Anthropic-Cybersecurity-Skills

Deploys Cloudflare Access with Cloudflare Tunnel for zero trust access to self-hosted apps, configuring identity-aware policies, device posture checks, and WARP client enrollment as a VPN replacement.

Apache-2.0Auto-check: notesBackend & APIs

Install Deploying Cloudflare Access For Zero Trust

skills CLI
$ npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill deploying-cloudflare-access-for-zero-trust -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mukul975/Anthropic-Cybersecurity-Skills deploying-cloudflare-access-for-zero-trust --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mukul975/Anthropic-Cybersecurity-Skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/deploying-cloudflare-access-for-zero-trust .claude/skills/deploying-cloudflare-access-for-zero-trust && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
deploying-cloudflare-access-for-zero-trust
GitHub stars
34k
Token cost
~3.8k tokens
SKILL.md length
663 words
Files
8 (incl. scripts, references, assets)
Skills in repo
637
Repo updated
First seen
Licence
Apache-2.0

At a glance

Deploys Cloudflare Access with Cloudflare Tunnel for zero trust access to self-hosted apps, configuring identity-aware policies, device posture checks, and WARP client enrollment as a VPN replacement.

  • Works in 6 steps: Create a Cloudflare Tunnel to Internal… → Configure Identity Provider Integration → Create Access Applications and Policies → …
  • Replacing VPN with Cloudflare One
  • SKILL.md covers When to Use, Prerequisites, Workflow and Key Concepts, plus 3 more sections
  • Runs Python scripts from its folder; calls curl and cloudflared; reaches api.cloudflare.com and developers.cloudflare.com; needs CF_API_TOKEN and OKTA_CLIENT_SECRET

What it does

Deploying Cloudflare Access For Zero Trust is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Deploys Cloudflare Access with Cloudflare Tunnel for zero trust access to self-hosted apps, configuring identity-aware policies, device posture checks, and WARP client enrollment as a VPN replacement. Use when replacing VPN with Cloudflare One, exposing internal apps without open inbound ports, or securing contractor/third-party access to specific applications.

Its SKILL.md is about 3.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 10 other files, including scripts, reference files and assets (for example `assets/template.md`, `references/api-reference.md` and `references/standards.md`).

It sits in Backend & APIs, covering OAuth and OpenID Connect. It works with Cloudflare. The repository describes itself as: 817 structured cybersecurity skills for AI agents · Mapped to 6 frameworks: MITRE ATT&CK, NIST CSF 2.0, MITRE ATLAS, D3FEND, NIST AI RMF & MITRE F3 (Fight Fraud) · agentskills.io…. The licence is Apache-2.0.

When your agent uses it

  • Replacing VPN with Cloudflare One
  • Exposing internal apps without open inbound ports
  • Securing contractor/third-party access to specific applications

Example prompts

  • “Use the deploying-cloudflare-access-for-zero-trust skill to deploy Cloudflare Access with Cloudflare Tunnel for zero trust access to self-hosted…”
  • “/deploying-cloudflare-access-for-zero-trust”

Requirements

  • Python 3
  • A credential in CF_API_TOKEN
  • A credential in OKTA_CLIENT_SECRET

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Create a Cloudflare Tunnel to Internal Applications
  2. Configure Identity Provider Integration
  3. Create Access Applications and Policies
  4. Deploy WARP Client for Device Enrollment
  5. Configure Device Posture Checks
  6. Set Up Audit Logging and Analytics

What it can do on your machine

Read from SKILL.md and the folder at commit 54a7988. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 2 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • curl
    • cloudflared

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • api.cloudflare.com
    • developers.cloudflare.com
    • github.com
    • apple.com
    • api.crowdstrike.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • CF_API_TOKEN
    • OKTA_CLIENT_SECRET
    • OKTA_API_TOKEN
    • AZURE_APP_CLIENT_SECRET
    • CS_API_CLIENT_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Deploying Cloudflare Access For Zero Trust loads about 3.8k tokens when it runs, and up to ~5.3k if it reads all its reference files. Until then it costs about 102 tokens; SKILL.md has 663 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~102
When it runs · the whole SKILL.md, loaded when a task matches
~3.8k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:68
    sudo dpkg -i cloudflared.deb
  • NoteRuns commands with sudoSKILL.md:103
    sudo cloudflared service install
  • NoteRuns commands with sudoSKILL.md:104
    sudo systemctl enable cloudflared
  • NoteRuns commands with sudoSKILL.md:105
    sudo systemctl start cloudflared
  • NoteRuns commands with sudoSKILL.md:241
    sudo cp cloudflare-root-ca.pem /usr/local/share/ca-certificates/cloudflare-root-ca.crt
  • NoteRuns commands with sudoSKILL.md:242
    sudo update-ca-certificates

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from mukul975/Anthropic-Cybersecurity-Skills at commit 54a7988, republished under its Apache-2.0 licence (© mukul975). 663 words, ~3,812 tokens.

Download SKILL.mdSave it as .claude/skills/deploying-cloudflare-access-for-zero-trust/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
deploying-cloudflare-access-for-zero-trust
description
Deploys Cloudflare Access with Cloudflare Tunnel for zero trust access to self-hosted apps, configuring identity-aware policies, device posture checks, and WARP client enrollment as a VPN replacement. Use when replacing VPN with Cloudflare One, exposing internal apps without open inbound ports, or securing contractor/third-party access to specific applications.
domain
cybersecurity
subdomain
zero-trust-architecture
tags
cloudflare, cloudflare-access, zero-trust, cloudflare-tunnel, warp, ztna, cloudflare-one
version
1.0
author
mahipal
license
Apache-2.0
atlas_techniques
AML.T0051, AML.T0054, AML.T0056
nist_ai_rmf
MEASURE-2.7, MEASURE-2.5, GOVERN-6.1, MAP-5.1
nist_csf
PR.AA-01, PR.AA-05, PR.IR-01, GV.PO-01
mitre_attack
T1133, T1078, T1190, T1021

Deploying Cloudflare Access for Zero Trust

When to Use

  • When replacing VPN infrastructure with identity-aware application access using Cloudflare One
  • When exposing self-hosted internal applications through Cloudflare Tunnel without opening inbound ports
  • When implementing ZTNA for a distributed workforce accessing web applications, SSH, and RDP services
  • When needing a cost-effective zero trust solution with integrated DLP, CASB, and SWG capabilities
  • When securing contractor and third-party access to specific applications without full network access

Do not use for applications requiring persistent UDP connections not supported by Cloudflare Tunnel, for environments requiring air-gapped or fully on-premises access control, or when regulatory requirements prohibit routing traffic through third-party cloud infrastructure.

Prerequisites

  • Cloudflare account with Zero Trust subscription (Free for up to 50 users, paid plans for larger teams)
  • Domain name managed by Cloudflare DNS (or ability to add CNAME records)
  • Linux, Windows, or macOS server to run cloudflared tunnel daemon
  • Identity provider: Okta, Microsoft Entra ID, Google Workspace, GitHub, or any SAML/OIDC provider
  • Cloudflare WARP client for device-level enrollment (optional but recommended)

Workflow

Step 1: Create a Cloudflare Tunnel to Internal Applications

Install cloudflared and create a persistent tunnel to expose internal services.

bash
# Install cloudflared on Ubuntu/Debian
curl -L https://github.com/cloudflare/cloudflared/releases/latest/download/cloudflared-linux-amd64.deb \
  -o cloudflared.deb
sudo dpkg -i cloudflared.deb

# Authenticate cloudflared with your Cloudflare account
cloudflared tunnel login

# Create a named tunnel
cloudflared tunnel create internal-apps
# Output: Created tunnel internal-apps with id xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx

# Configure tunnel routes to internal applications
cat > ~/.cloudflared/config.yml << 'EOF'
tunnel: xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx
credentials-file: /home/admin/.cloudflared/xxxxxxxx-xxxx-xxxx-xxxx-xxxxxxxxxxxx.json

ingress:
  - hostname: wiki.company.com
    service: http://localhost:8080
  - hostname: git.company.com
    service: http://10.1.1.50:3000
  - hostname: grafana.company.com
    service: http://10.1.1.60:3000
  - hostname: ssh.company.com
    service: ssh://localhost:22
  - hostname: rdp.company.com
    service: rdp://10.1.1.100:3389
  # Catch-all rule (required)
  - service: http_status:404
EOF

# Route DNS to the tunnel
cloudflared tunnel route dns internal-apps wiki.company.com
cloudflared tunnel route dns internal-apps git.company.com
cloudflared tunnel route dns internal-apps grafana.company.com

# Run tunnel as a systemd service
sudo cloudflared service install
sudo systemctl enable cloudflared
sudo systemctl start cloudflared

# Verify tunnel status
cloudflared tunnel info internal-apps
Step 2: Configure Identity Provider Integration

Set up authentication with your organization's identity provider.

bash
# Using Cloudflare API to configure Okta as IdP
curl -X PUT "https://api.cloudflare.com/client/v4/accounts/{account_id}/access/identity_providers" \
  -H "Authorization: Bearer ${CF_API_TOKEN}" \
  -H "Content-Type: application/json" \
  --data '{
    "name": "Corporate Okta",
    "type": "okta",
    "config": {
      "client_id": "OKTA_CLIENT_ID",
      "client_secret": "OKTA_CLIENT_SECRET",
      "okta_account": "company.okta.com",
      "api_token": "OKTA_API_TOKEN",
      "claims": ["email", "groups", "name"],
      "email_claim_name": "email"
    }
  }'

# Configure Microsoft Entra ID as additional IdP
curl -X POST "https://api.cloudflare.com/client/v4/accounts/{account_id}/access/identity_providers" \
  -H "Authorization: Bearer ${CF_API_TOKEN}" \
  -H "Content-Type: application/json" \
  --data '{
    "name": "Microsoft Entra ID",
    "type": "azureAD",
    "config": {
      "client_id": "AZURE_APP_CLIENT_ID",
      "client_secret": "AZURE_APP_CLIENT_SECRET",
      "directory_id": "AZURE_TENANT_ID",
      "support_groups": true,
      "claims": ["email", "groups", "name"]
    }
  }'
Step 3: Create Access Applications and Policies

Define Access applications with identity-aware policies for each internal service.

bash
# Create Access application for internal wiki
curl -X POST "https://api.cloudflare.com/client/v4/accounts/{account_id}/access/apps" \
  -H "Authorization: Bearer ${CF_API_TOKEN}" \
  -H "Content-Type: application/json" \
  --data '{
    "name": "Internal Wiki",
    "domain": "wiki.company.com",
    "type": "self_hosted",
    "session_duration": "8h",
    "auto_redirect_to_identity": true,
    "http_only_cookie_attribute": true,
    "same_site_cookie_attribute": "lax",
    "logo_url": "https://company.com/wiki-logo.png",
    "allowed_idps": ["OKTA_IDP_ID", "AZURE_IDP_ID"]
  }'

# Create Allow policy for the wiki application
curl -X POST "https://api.cloudflare.com/client/v4/accounts/{account_id}/access/apps/{app_id}/policies" \
  -H "Authorization: Bearer ${CF_API_TOKEN}" \
  -H "Content-Type: application/json" \
  --data '{
    "name": "Allow Engineering Team",
    "decision": "allow",
    "precedence": 1,
    "include": [
      {"group": {"id": "ENGINEERING_GROUP_ID"}},
      {"okta": {"name": "Engineering", "identity_provider_id": "OKTA_IDP_ID"}}
    ],
    "require": [
      {"device_posture": {"integration_uid": "CROWDSTRIKE_INTEGRATION_ID"}}
    ]
  }'

# Create Access application for SSH access
curl -X POST "https://api.cloudflare.com/client/v4/accounts/{account_id}/access/apps" \
  -H "Authorization: Bearer ${CF_API_TOKEN}" \
  -H "Content-Type: application/json" \
  --data '{
    "name": "SSH Access",
    "domain": "ssh.company.com",
    "type": "ssh",
    "session_duration": "4h",
    "auto_redirect_to_identity": true
  }'
Step 4: Deploy WARP Client for Device Enrollment

Enroll corporate devices using Cloudflare WARP for private network access and device posture.

bash
# Create device enrollment rule
curl -X POST "https://api.cloudflare.com/client/v4/accounts/{account_id}/devices/policy" \
  -H "Authorization: Bearer ${CF_API_TOKEN}" \
  -H "Content-Type: application/json" \
  --data '{
    "name": "Corporate Device Enrollment",
    "match": "identity.email matches \".*@company\\.com$\"",
    "precedence": 100,
    "enabled": true,
    "gateway_unique_id": "GATEWAY_ID",
    "support_url": "https://helpdesk.company.com/warp-help"
  }'

# Install WARP on macOS via MDM (Jamf/Intune)
# Download: https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/download-warp/
# Deploy with MDM configuration profile:
cat > warp_mdm_config.plist << 'EOF'
<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
<plist version="1.0">
<dict>
    <key>organization</key>
    <string>company</string>
    <key>auto_connect</key>
    <integer>1</integer>
    <key>switch_locked</key>
    <true/>
    <key>onboarding</key>
    <false/>
</dict>
</plist>
EOF

# Install Cloudflare root certificate for TLS inspection
# Download from: https://developers.cloudflare.com/cloudflare-one/connections/connect-devices/warp/user-side-certificates/
sudo cp cloudflare-root-ca.pem /usr/local/share/ca-certificates/cloudflare-root-ca.crt
sudo update-ca-certificates

# Configure split tunnel to route private network through WARP
curl -X PUT "https://api.cloudflare.com/client/v4/accounts/{account_id}/devices/policy/{policy_id}/fallback_domains" \
  -H "Authorization: Bearer ${CF_API_TOKEN}" \
  -H "Content-Type: application/json" \
  --data '[
    {"suffix": "internal.corp", "description": "Internal corporate domain"},
    {"suffix": "10.0.0.0/8", "description": "Private network range"}
  ]'
Step 5: Configure Device Posture Checks

Integrate endpoint security signals into Access policies.

bash
# Add CrowdStrike device posture integration
curl -X POST "https://api.cloudflare.com/client/v4/accounts/{account_id}/devices/posture/integration" \
  -H "Authorization: Bearer ${CF_API_TOKEN}" \
  -H "Content-Type: application/json" \
  --data '{
    "name": "CrowdStrike Falcon",
    "type": "crowdstrike_s2s",
    "config": {
      "api_url": "https://api.crowdstrike.com",
      "client_id": "CS_API_CLIENT_ID",
      "client_secret": "CS_API_CLIENT_SECRET",
      "customer_id": "CS_CUSTOMER_ID"
    },
    "interval": "10m"
  }'

# Create device posture rule for disk encryption
curl -X POST "https://api.cloudflare.com/client/v4/accounts/{account_id}/devices/posture" \
  -H "Authorization: Bearer ${CF_API_TOKEN}" \
  -H "Content-Type: application/json" \
  --data '{
    "name": "Disk Encryption Required",
    "type": "disk_encryption",
    "match": [{"platform": "windows"}, {"platform": "mac"}],
    "input": {"requireAll": true}
  }'

# Create device posture rule for OS version
curl -X POST "https://api.cloudflare.com/client/v4/accounts/{account_id}/devices/posture" \
  -H "Authorization: Bearer ${CF_API_TOKEN}" \
  -H "Content-Type: application/json" \
  --data '{
    "name": "Minimum OS Version",
    "type": "os_version",
    "match": [{"platform": "windows"}],
    "input": {"version": "10.0.19045", "operator": ">="}
  }'
Step 6: Set Up Audit Logging and Analytics

Configure logging for access decisions and tunnel health monitoring.

bash
# Enable Logpush for Access audit logs to S3
curl -X POST "https://api.cloudflare.com/client/v4/accounts/{account_id}/logpush/jobs" \
  -H "Authorization: Bearer ${CF_API_TOKEN}" \
  -H "Content-Type: application/json" \
  --data '{
    "name": "access-audit-logs",
    "output_options": {
      "field_names": ["RayID","Action","Allowed","AppDomain","AppUUID","Connection","Country","CreatedAt","Email","IPAddress","PurposeJustificationPrompt","PurposeJustificationResponse","TemporaryAccessDuration","UserUID"],
      "timestamp_format": "rfc3339"
    },
    "destination_conf": "s3://security-logs-bucket/cloudflare-access/?region=us-east-1&access-key-id=AKID&secret-access-key=SECRET",
    "dataset": "access_requests",
    "enabled": true
  }'

# Query access logs via GraphQL Analytics API
curl -X POST "https://api.cloudflare.com/client/v4/graphql" \
  -H "Authorization: Bearer ${CF_API_TOKEN}" \
  -H "Content-Type: application/json" \
  --data '{
    "query": "{ viewer { accounts(filter: {accountTag: \"ACCOUNT_ID\"}) { accessLoginRequestsAdaptiveGroups(filter: {datetime_gt: \"2026-02-22T00:00:00Z\"}, limit: 100, orderBy: [count_DESC]) { dimensions { action appName userEmail country } count } } } }"
  }'

Key Concepts

TermDefinition
Cloudflare TunnelEncrypted outbound-only connection from your infrastructure to Cloudflare's network, exposing internal services without opening inbound firewall ports
Cloudflare AccessIdentity-aware reverse proxy evaluating every request against access policies before granting access to protected applications
WARP ClientCloudflare's endpoint agent that routes device traffic through Cloudflare's network for policy enforcement and private network access
Access ApplicationConfiguration object defining a protected resource (self-hosted, SaaS, or infrastructure) with associated access policies
Device PostureEndpoint health signals (OS version, disk encryption, EDR status) evaluated as conditions in Access policies
Cloudflare OneUnified SASE platform combining ZTNA (Access), SWG (Gateway), CASB, DLP, and RBI
Show full SKILL.md (285 more words)Show less

Tools & Systems

  • Cloudflare Access: Identity-aware application proxy providing per-request authorization
  • Cloudflare Tunnel (cloudflared): Daemon creating encrypted tunnels from internal networks to Cloudflare edge
  • WARP Client: Cross-platform endpoint agent for device enrollment, DNS filtering, and private network routing
  • Cloudflare Gateway: Secure Web Gateway providing DNS/HTTP filtering and DLP inspection
  • Cloudflare Logpush: Real-time log streaming to external SIEM and storage destinations
  • Access for Infrastructure: SSH and RDP access with short-lived certificates and session recording

Common Scenarios

Scenario: Startup with 200 Employees Deploying Zero Trust from Scratch

Context: A SaaS startup with 200 employees and no existing VPN wants to provide secure access to internal tools (Grafana, internal APIs, staging environments) running on AWS. Budget is limited, and the team has no dedicated security staff.

Approach:

  1. Start with Cloudflare Zero Trust free tier (up to 50 users) for proof of concept
  2. Deploy one cloudflared tunnel on an EC2 instance in the production VPC
  3. Expose Grafana, internal wiki, and staging apps through tunnel with DNS routing
  4. Configure Google Workspace as IdP for SSO authentication
  5. Create Access policies requiring @company.com email domain for all applications
  6. Add device posture checks for disk encryption and OS version
  7. Upgrade to paid plan and deploy WARP client to all employee laptops via MDM
  8. Enable Gateway DNS filtering and HTTP inspection for malware protection
  9. Configure Logpush to send access logs to Datadog for monitoring

Pitfalls: Cloudflare root certificate must be installed on all devices for TLS inspection to work; some applications may break with TLS interception. Tunnel failover requires running multiple cloudflared instances or using Cloudflare's replicas feature. Access policies should always include a default deny rule. WebSocket applications may require specific tunnel configuration.

Output Format

Cloudflare Zero Trust Deployment Report
==================================================
Organization: StartupCorp
Team Name: startupcorp
Deployment Date: 2026-02-23

TUNNEL INFRASTRUCTURE:
  Active Tunnels: 2 (primary + failover)
  Tunnel Status: Healthy
  Connected Edge: Washington DC, Ashburn
  Ingress Routes: 8

ACCESS APPLICATIONS:
  Self-Hosted Apps: 6
  SaaS Apps: 3
  SSH/Infrastructure: 2
  Total Policies: 15

DEVICE ENROLLMENT:
  Enrolled Devices: 187 / 200
  WARP Connected: 182 / 187 (97.3%)
  Posture Compliant: 175 / 187 (93.6%)

ACCESS METRICS (last 30 days):
  Total Requests: 89,432
  Allowed: 88,756 (99.2%)
  Blocked: 676 (0.8%)
  Unique Users: 195
  Countries: 12
  Avg Session Duration: 6.2 hours

© mukul975, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files (scripts, references, assets) in skills/deploying-cloudflare-access-for-zero-trust of mukul975/Anthropic-Cybersecurity-Skills.

  • SKILL.md
  • LICENSE
  • assets/template.md
  • references/api-reference.md
  • references/standards.md
  • references/workflows.md
  • scripts/agent.py
  • scripts/process.py

Open the folder on GitHubat commit 54a7988

Compare with similar skills

Deploying Cloudflare Access For Zero Trust next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Deploying Cloudflare Access For Zero Trust compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Deploying Cloudflare Access For Zero Trust this skillmukul975/Anthropic-Cybersecurity-Skills34k—~3.8kAutomated safety check: NotesApache-2.0
Integration Generatordafthunk-com/dafthunk134—~2.3kAutomated safety check: PassMIT
Nuxt Studiosecondsky/claude-skills227—~2.8kAutomated safety check: PassMIT
Better Authsecondsky/claude-skills227—~7.5kAutomated safety check: PassMIT
Building MCP Server On CloudflareCommandCodeAI/agent-skills132—~1.5kAutomated safety check: PassMIT
Security Reviewdoorkeeper-gem/doorkeeper5.5k—~1.4kAutomated safety check: PassMIT

Similar skills

  • Integration Generator

    dafthunk-com/dafthunk

    Generate new OAuth integration providers for Dafthunk with backend providers, type definitions, frontend configurations, and integration nodes

    134 GitHub stars~2.3k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Nuxt Studio

    secondsky/claude-skills

    This skill should be used when the user asks to "set up Nuxt Studio", "configure Studio OAuth", "deploy Studio to Cloudflare", "add visual editor to Nuxt", "configure studio.domain.com subdomain"…

    227 GitHub stars~2.8k tokensUpdated 10 days ago
    Backend & APIsAuto-check passed
  • Better Auth

    secondsky/claude-skills

    Skill for integrating Better Auth - comprehensive TypeScript authentication framework for Cloudflare D1, Next.js, Nuxt, and 15+ frameworks.

    227 GitHub stars~7.5k tokensUpdated 10 days ago
    Backend & APIsAuto-check passed
  • Building MCP Server On Cloudflare

    CommandCodeAI/agent-skills

    Builds remote MCP (Model Context Protocol) servers on Cloudflare Workers with tools, OAuth authentication, and production deployment.

    132 GitHub stars~1.5k tokensUpdated 7 mo ago
    Agent WorkflowsAuto-check passed
  • Security Review

    doorkeeper-gem/doorkeeper

    Verify that code changes do not introduce OAuth security vulnerabilities.

    5.5k GitHub stars~1.4k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Better Auth security hardening: rate limits, secrets, CSRF, trusted origins, cookies, sessions, OAuth tokens, and audit logging.

    4.8k GitHub stars~896 tokensUpdated yesterday
    Backend & APIsAuto-check passed

More from mukul975/Anthropic-Cybersecurity-Skills

All 637 skills in this repo
  • Campaign Attribution Evidence Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Weighs infrastructure, TTP, malware code and timing evidence with the Diamond Model and competing hypotheses to reach a confidence-rated attribution.

    34k GitHub stars~2.3k tokensUpdated 1 mo ago
    Auto-check passed
  • Go Malware Analysis in Ghidra

    mukul975/Anthropic-Cybersecurity-Skills

    Walks through reverse engineering Go-compiled malware in Ghidra: parsing buildinfo and pclntab, recovering stripped function names and extracting dependencies.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • LNK and Jump List Forensics

    mukul975/Anthropic-Cybersecurity-Skills

    Guides forensic analysis of Windows LNK shortcut files and Jump Lists with LECmd, JLECmd and manual parsing to show file access and program execution.

    34k GitHub stars~2.8k tokensUpdated 1 mo ago
    Auto-check passed
  • Malware Persistence Analysis with Autoruns

    mukul975/Anthropic-Cybersecurity-Skills

    Hunts Windows malware persistence with Sysinternals Autoruns, covering run keys, services, scheduled tasks and drivers, with baseline comparison.

    34k GitHub stars~1.2k tokensUpdated 1 mo ago
    Auto-check passed
  • NTFS MFT Deleted File Recovery

    mukul975/Anthropic-Cybersecurity-Skills

    Guides a Windows forensic examination of the NTFS Master File Table to recover deleted-file evidence, build timelines and spot timestomping.

    34k GitHub stars~2.7k tokensUpdated 1 mo ago
    Auto-check passed
  • Network Covert Channel Analysis

    mukul975/Anthropic-Cybersecurity-Skills

    Detects DNS tunneling, ICMP exfiltration and HTTP-based covert channels in packet captures and DNS logs when hunting for hidden command-and-control traffic.

    34k GitHub stars~2k tokensUpdated 1 mo ago
    Auto-check passed

Works with

Questions about Deploying Cloudflare Access For Zero Trust

What does Deploying Cloudflare Access For Zero Trust do?

Deploys Cloudflare Access with Cloudflare Tunnel for zero trust access to self-hosted apps, configuring identity-aware policies, device posture checks, and WARP client enrollment as a VPN replacement. Deploying Cloudflare Access For Zero Trust is an agent skill from mukul975/Anthropic-Cybersecurity-Skills. Deploys Cloudflare Access with Cloudflare Tunnel for zero trust access to self-hosted apps, configuring identity-aware policies, device posture checks, and WARP client enrollment as a VPN replacement.

When should I use Deploying Cloudflare Access For Zero Trust?

Deploying Cloudflare Access For Zero Trust fits situations like: replacing VPN with Cloudflare One; exposing internal apps without open inbound ports; securing contractor/third-party access to specific applications.

How do I install Deploying Cloudflare Access For Zero Trust in Claude Code?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill deploying-cloudflare-access-for-zero-trust -a claude-code`. Or copy the skill folder (skills/deploying-cloudflare-access-for-zero-trust in mukul975/Anthropic-Cybersecurity-Skills) into .claude/skills/deploying-cloudflare-access-for-zero-trust in your project. Claude Code loads it when a task matches its description.

How do I install Deploying Cloudflare Access For Zero Trust in Codex?

Run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill deploying-cloudflare-access-for-zero-trust -a codex`. Or copy the skill folder (skills/deploying-cloudflare-access-for-zero-trust in mukul975/Anthropic-Cybersecurity-Skills) into .agents/skills/deploying-cloudflare-access-for-zero-trust in your project. Codex loads it when a task matches its description.

Can I use Deploying Cloudflare Access For Zero Trust in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mukul975/Anthropic-Cybersecurity-Skills --skill deploying-cloudflare-access-for-zero-trust -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/deploying-cloudflare-access-for-zero-trust, .gemini/skills/deploying-cloudflare-access-for-zero-trust, .github/skills/deploying-cloudflare-access-for-zero-trust and .opencode/skills/deploying-cloudflare-access-for-zero-trust in your project.

What does Deploying Cloudflare Access For Zero Trust need to run?

Going by SKILL.md and its folder, Deploying Cloudflare Access For Zero Trust needs Python for the scripts in its folder, the command-line tools its instructions call (curl and cloudflared) and credentials named CF_API_TOKEN, OKTA_CLIENT_SECRET, OKTA_API_TOKEN and AZURE_APP_CLIENT_SECRET. Our summary lists: Python 3; A credential in CF_API_TOKEN; A credential in OKTA_CLIENT_SECRET.

Does Deploying Cloudflare Access For Zero Trust access the network?

SKILL.md names 5 domains. In commands or code: api.cloudflare.com, developers.cloudflare.com, github.com, apple.com and api.crowdstrike.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Deploying Cloudflare Access For Zero Trust safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Deploying Cloudflare Access For Zero Trust use?

Deploying Cloudflare Access For Zero Trust is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Deploying Cloudflare Access For Zero Trust use?

About 3.8k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.5k tokens, read only when the agent opens those files.

What are the alternatives to Deploying Cloudflare Access For Zero Trust?

Skills that share tags, products or a category with Deploying Cloudflare Access For Zero Trust: Integration Generator (dafthunk-com/dafthunk, 134 stars), Nuxt Studio (secondsky/claude-skills, 227 stars), Better Auth (secondsky/claude-skills, 227 stars) and Building MCP Server On Cloudflare (CommandCodeAI/agent-skills, 132 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Deploying Cloudflare Access For Zero Trust?

mukul975 (a GitHub user) maintains it in mukul975/Anthropic-Cybersecurity-Skills, which has 33,922 GitHub stars. The repository holds 637 skills in this directory. The repository was last updated on August 31, 2026.

Source: mukul975/Anthropic-Cybersecurity-Skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.