Agent skill

Blueprint Cloudflare Security

by receptron in receptron/mulmoterminal

Review the finished Worker against OWASP Top 10:2025, fix what is exploitable, prove each fix with a test, and report.

MITAuto-check: notesSecurity

Install Blueprint Cloudflare Security

skills CLI
$ npx skills add receptron/mulmoterminal --skill blueprint-cloudflare-security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install receptron/mulmoterminal blueprint-cloudflare-security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/receptron/mulmoterminal.git skills-src && mkdir -p .claude/skills && cp -r skills-src/blueprints/cloudflare/skills/security .claude/skills/blueprint-cloudflare-security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
blueprint-cloudflare-security
GitHub stars
237
Token cost
~1.2k tokens
SKILL.md length
661 words
Files
1
Skills in repo
30
Repo updated
First seen
Licence
MIT

At a glance

Review the finished Worker against OWASP Top 10:2025, fix what is exploitable, prove each fix with a test, and report.

  • Works in 4 steps: Context. Read .blueprint/spec.md (above… → Audit, category by category (the list… → Fix every HIGH and MEDIUM finding, and… → …
  • Tasks that involve Web application vulnerabilities
  • SKILL.md covers Method, What to look at in this app…, What the check sends, and must… and The report, plus 1 more section
  • Calls yarn, wrangler and git

What it does

Blueprint Cloudflare Security is an agent skill from receptron/mulmoterminal. Review the finished Worker against OWASP Top 10:2025, fix what is exploitable, prove each fix with a test, and report.

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Web application vulnerabilities. It works with Cloudflare and Cloudflare Workers. The repository describes itself as: Run multiple Claude Code and Codex sessions in parallel — a browser terminal grid that shows which agent needs you. Local, tmux-backed, MIT. The licence is MIT.

When your agent uses it

  • Tasks that involve Web application vulnerabilities

Example prompts

  • “/blueprint-cloudflare-security”

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Context. Read .blueprint/spec.md (above all "必ず詰める点"), then src/worker/, src/client/,
  2. Audit, category by category (the list below). For each place input enters, trace it to where it is used.
  3. Fix every HIGH and MEDIUM finding, and add a test to test/security.test.ts that fails without the fix.
  4. Report in .blueprint/security-review.md (format below).

What it can do on your machine

Read from SKILL.md and the folder at commit 0b9f076. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • yarn
    • wrangler
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use yarn, wrangler and git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Blueprint Cloudflare Security loads about 1.2k tokens when it runs. Until then it costs about 37 tokens; SKILL.md has 661 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~37
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:33
    ngler secrets, and `.dev.vars` (and any `.env`) listed in `.gitignore`; cookies `HttpOnly`, `Secure`,
  • NoteMentions a .env fileSKILL.md:52
    - `.dev.vars` / `.env`, if present, ignored by `.gitignore`.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from receptron/mulmoterminal at commit 0b9f076, republished under its MIT licence (© receptron). 661 words, ~1,175 tokens.

Download SKILL.mdSave it as .claude/skills/blueprint-cloudflare-security/SKILL.md (or your agent's skills folder).
name
blueprint-cloudflare-security
description
Review the finished Worker against OWASP Top 10:2025, fix what is exploitable, prove each fix with a test, and report.

Security review

The app is built and runs. Before it is published, review it the way an attacker would read it, fix what is exploitable, and leave a report the person can read. The check does not take your word for it: it starts the Worker with wrangler dev and sends it the requests an attack would send.

Method

  1. Context. Read .blueprint/spec.md (above all "必ず詰める点"), then src/worker/, src/client/, wrangler.jsonc, public/_headers and package.json. Note who may do what, where input enters, what is stored.
  2. Audit, category by category (the list below). For each place input enters, trace it to where it is used.
  3. Fix every HIGH and MEDIUM finding, and add a test to test/security.test.ts that fails without the fix.
  4. Report in .blueprint/security-review.md (format below).

Severity: HIGH is directly exploitable (read or change someone's data, bypass sign-in, run code). MEDIUM needs a specific condition but the impact is real. LOW is defence in depth. Report a finding only when you can state how it is exploited and you are at least 70% sure. Do not report denial of service, rate limits, or missing validation on a field that cannot cause harm.

What to look at in this app (OWASP Top 10:2025)

  • A01 Broken Access Control — the app is public: every /api route enforces the spec's sign-in and roles in the Worker; with accounts, a row is read or changed only by whoever may.
  • A02 Security Misconfiguration — security headers on every response: the Worker's for /api/*, and public/_headers for the static files, which never go through the Worker; no permissive CORS.
  • A03 Software Supply Chain Failures — yarn audit --groups dependencies has no high or critical.
  • A04 Cryptographic Failures — passwords as salted PBKDF2 (Web Crypto), compared in constant time; secrets as wrangler secrets, and .dev.vars (and any .env) listed in .gitignore; cookies HttpOnly, Secure, SameSite=Lax.
  • A05 Injection — SQL only with bound parameters; the screen never renders input as HTML.
  • A06 Insecure Design — the spec's rules are enforced in the Worker, not only on the screen.
  • A07 Authentication Failures — a new session at sign-in; sign-out ends it; no default password in the code.
  • A08 Software or Data Integrity Failures — nothing from a request picks code to run; an uploaded file is checked for type and size.
  • A09 Security Logging and Alerting Failures — sign-in failures and changes to data are logged (console.log reaches wrangler tail), without passwords, cookies or secrets.
  • A10 Mishandling of Exceptional Conditions — every error reaches one handler that answers JSON without a stack; a failed check refuses rather than lets through.
Show full SKILL.md (238 more words)Show less

What the check sends, and must get back

  • A POST under /api from Origin: https://attacker.example → 403, before routing and sign-in.
  • A POST under /api with a malformed JSON body → 400, from the one place the Worker reads bodies, with no stack trace or parser message.
  • / and /api/health: Content-Security-Policy with frame-ancestors 'none', X-Content-Type-Options: nosniff, no X-Powered-By.
  • .dev.vars / .env, if present, ignored by .gitignore.

The report

.blueprint/security-review.md, in the spec's language. One section per category, its heading naming the id (## A01 … through ## A10 …), every finding on a line of its own:

- HIGH fixed: <what was wrong, how it could be exploited> — <what changed, which test proves it>
- LOW accepted: <what, and why it is acceptable for this app>

The state is fixed, open or accepted; a HIGH or MEDIUM may be neither open nor accepted. A category with nothing to report says what was checked and "指摘なし".

Done when the check passes: the report covers A01–A10 with nothing HIGH or MEDIUM left open, the tests pass, the audit is clean, and the running Worker refuses the cross-site change and the malformed body and sends the headers.

Always

  • Read .blueprint/spec.md first. It is the agreed specification; do not widen it.
  • When you need a decision, ask it through the blueprint question tool and stop. Do not guess.
  • Do not run git init: a new repository loses the folder's trust and the next unattended step stops at Claude Code's trust prompt. The user adds git themselves after the build if they want it.
  • Say you are done by stopping; the executor runs the check. Do not claim success yourself.

© receptron, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in blueprints/cloudflare/skills/security of receptron/mulmoterminal.

Open the folder on GitHubat commit 0b9f076

Compare with similar skills

Blueprint Cloudflare Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Blueprint Cloudflare Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Blueprint Cloudflare Security this skillreceptron/mulmoterminal237—~1.2kAutomated safety check: NotesMIT
Implementing Cloud Waf Rulesmukul975/Anthropic-Cybersecurity-Skills34k—~2.9kAutomated safety check: PassApache-2.0
Detecting SQL Injection Via Waf Logsmukul975/Anthropic-Cybersecurity-Skills34k—~564Automated safety check: PassApache-2.0
Hunt Cache Poisonelementalsouls/Claude-BugHunter4.8k—~5.7kAutomated safety check: PassMIT
Cloudflare Workers Securitysecondsky/claude-skills227—~1.9kAutomated safety check: PassMIT
Cloudflare Browser Renderingcloudflare/moltworker10k—~742Automated safety check: PassApache-2.0

Similar skills

  • Implementing Cloud Waf Rules

    mukul975/Anthropic-Cybersecurity-Skills

    Deploys and tunes Web Application Firewall rules on AWS WAF, Azure WAF, and Cloudflare, covering managed rule sets, custom business-logic rules, rate limiting, bot management, and false-positive…

    34k GitHub stars~2.9k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Detecting SQL Injection Via Waf Logs

    mukul975/Anthropic-Cybersecurity-Skills

    Analyze WAF (ModSecurity/AWS WAF/Cloudflare) logs to detect SQL injection attack campaigns.

    34k GitHub stars~564 tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Hunt Cache Poison

    elementalsouls/Claude-BugHunter

    Hunting skill for cache poison vulnerabilities. An agent skill from elementalsouls/Claude-BugHunter.

    4.8k GitHub stars~5.7k tokensUpdated yesterday
    SecurityAuto-check passed
  • Cloudflare Workers Security

    secondsky/claude-skills

    Cloudflare Workers security with authentication, CORS, rate limiting, input validation.

    227 GitHub stars~1.9k tokensUpdated 11 days ago
    Backend & APIsAuto-check passed
  • Cloudflare Browser Rendering

    cloudflare/moltworker

    Official

    Drives headless Chrome through Cloudflare Browser Rendering over a CDP WebSocket to take screenshots, navigate and scrape pages, and record multi-page videos.

    10k GitHub stars~742 tokensUpdated 5 mo ago
    Productivity & AutomationAuto-check passed
  • Cloudflare

    hodgef/apiker

    Comprehensive Cloudflare platform skill covering Workers, Pages, storage (KV, D1, R2), AI (Workers AI, Vectorize, Agents SDK), feature flags (Flagship), networking (Tunnel, Spectrum), security (WAF…

    127 GitHub starsUsed in 7 repos~2.2k tokens
    DevOps & CloudAuto-check passed

More from receptron/mulmoterminal

All 30 skills in this repo
  • Mulmoterminal Bug Report

    receptron/mulmoterminal

    Help desk for "MulmoTerminal is broken". An agent skill from receptron/mulmoterminal.

    237 GitHub stars~1.7k tokensUpdated today
    Auto-check passed
  • Mulmoterminal Decisions

    receptron/mulmoterminal

    Check what this project's humans have already been asked, and how they answered, before asking them something similar.

    237 GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Mulmoterminal Notify

    receptron/mulmoterminal

    Decide which moments MulmoTerminal beeps or pushes for, and what each one plays — soundKinds, sounds and pushKinds in ~/.mulmoterminal/config.json, plus a per-project sound / sounds in…

    237 GitHub stars~1.8k tokensUpdated today
    Auto-check passed
  • Mulmoterminal Theme

    receptron/mulmoterminal

    Build a colour scheme of your own for MulmoTerminal — one that joins Midnight, Nord, Daylight and Solarized in Settings' theme picker and can then be pinned per project.

    237 GitHub stars~2.5k tokensUpdated today
    Auto-check passed
  • Blueprint Ask Answer

    receptron/mulmoterminal

    Answer each question from the named documents only, quoting where the answer is written, or saying plainly that the documents do not say — changing nothing yet.

    237 GitHub stars~780 tokensUpdated today
    Auto-check passed
  • Blueprint Compare Pair

    receptron/mulmoterminal

    Pair every article of the old version with its article in the new one, and say whether each changed, was added or was removed — writing .blueprint/comparison.json and changing no document.

    237 GitHub stars~678 tokensUpdated today
    Auto-check passed

Categories

Questions about Blueprint Cloudflare Security

What does Blueprint Cloudflare Security do?

Review the finished Worker against OWASP Top 10:2025, fix what is exploitable, prove each fix with a test, and report. Blueprint Cloudflare Security is an agent skill from receptron/mulmoterminal. Review the finished Worker against OWASP Top 10:2025, fix what is exploitable, prove each fix with a test, and report.

When should I use Blueprint Cloudflare Security?

Blueprint Cloudflare Security fits situations like: tasks that involve Web application vulnerabilities.

How do I install Blueprint Cloudflare Security in Claude Code?

Run `npx skills add receptron/mulmoterminal --skill blueprint-cloudflare-security -a claude-code`. Or copy the skill folder (blueprints/cloudflare/skills/security in receptron/mulmoterminal) into .claude/skills/blueprint-cloudflare-security in your project. Claude Code loads it when a task matches its description.

How do I install Blueprint Cloudflare Security in Codex?

Run `npx skills add receptron/mulmoterminal --skill blueprint-cloudflare-security -a codex`. Or copy the skill folder (blueprints/cloudflare/skills/security in receptron/mulmoterminal) into .agents/skills/blueprint-cloudflare-security in your project. Codex loads it when a task matches its description.

Can I use Blueprint Cloudflare Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add receptron/mulmoterminal --skill blueprint-cloudflare-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/blueprint-cloudflare-security, .gemini/skills/blueprint-cloudflare-security, .github/skills/blueprint-cloudflare-security and .opencode/skills/blueprint-cloudflare-security in your project.

What does Blueprint Cloudflare Security need to run?

Going by SKILL.md and its folder, Blueprint Cloudflare Security needs the command-line tools its instructions call (yarn, wrangler and git).

Does Blueprint Cloudflare Security access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Blueprint Cloudflare Security safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Blueprint Cloudflare Security use?

Blueprint Cloudflare Security is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Blueprint Cloudflare Security use?

About 1.2k tokens (SKILL.md is roughly 4.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Blueprint Cloudflare Security?

Skills that share tags, products or a category with Blueprint Cloudflare Security: Implementing Cloud Waf Rules (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Detecting SQL Injection Via Waf Logs (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Hunt Cache Poison (elementalsouls/Claude-BugHunter, 4.8k stars) and Cloudflare Workers Security (secondsky/claude-skills, 227 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Blueprint Cloudflare Security?

receptron (a GitHub organization) maintains it in receptron/mulmoterminal, which has 237 GitHub stars. The repository holds 30 skills in this directory. The repository was last updated on October 9, 2026.

Source: receptron/mulmoterminal on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.