Agent skill

Cloudflare Zero Trust

by sickn33 in sickn33/agentic-awesome-skills

Protect internal apps with Cloudflare Access, device posture, and Zero Trust policies.

MITAuto-check: warningsDevOps & Cloud

Install Cloudflare Zero Trust

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add sickn33/agentic-awesome-skills --skill cloudflare-zero-trust -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sickn33/agentic-awesome-skills cloudflare-zero-trust --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cloudflare-zero-trust .claude/skills/cloudflare-zero-trust && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cloudflare-zero-trust
GitHub stars
47k
Used in
2 other repos
Token cost
~2.8k tokens
SKILL.md length
526 words
Files
1
Skills in repo
1,354
Repo updated
First seen
Licence
MIT

At a glance

Protect internal apps with Cloudflare Access, device posture, and Zero Trust policies.

  • Works in 3 steps: Go to Settings > WARP Client > Device… → Add checks → Reference posture checks in Access…
  • DevOps & Cloud work in your project
  • SKILL.md covers When to Use, Prerequisites, Cloudflare Tunnel Setup and Access Policies, plus 7 more sections
  • Calls cloudflared, curl and apt; reaches api.cloudflare.com and pkg.cloudflare.com; needs CF_API_TOKEN and TUNNEL_TOKEN

What it does

Cloudflare Zero Trust is an agent skill from sickn33/agentic-awesome-skills. Protect internal apps with Cloudflare Access, device posture, and Zero Trust policies.

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Requires the relevant OS/platform tooling and privileged access where noted. Docs-only; helper scripts and templates not bundled.

It sits in DevOps & Cloud. It works with Cloudflare. The repository describes itself as: AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 2,400+ agentic skills. Includes… The licence is MIT.

When your agent uses it

  • DevOps & Cloud work in your project

Example prompts

  • “/cloudflare-zero-trust”

Requirements

  • Docker
  • A credential in TUNNEL_TOKEN
  • A credential in CF_API_TOKEN
  • Compatibility (from SKILL.md): Requires the relevant OS/platform tooling and privileged access where noted. Docs-only; helper scripts and templates not bundled.

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Go to Settings > WARP Client > Device posture.
  2. Add checks
  3. Reference posture checks in Access policies under Require rules.

What it can do on your machine

Read from SKILL.md and the folder at commit ec02547. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • cloudflared
    • curl
    • apt
    • docker
    • brew

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • api.cloudflare.com
    • pkg.cloudflare.com
    • connectivity.cloudflare.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • CF_API_TOKEN
    • TUNNEL_TOKEN
    • CLIENT_SECRET
    • CF_CLIENT_SECRET

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires the relevant OS/platform tooling and privileged access where noted. Docs-only; helper scripts and templates not bundled.

    From compatibility in the SKILL.md frontmatter.

Context cost

Cloudflare Zero Trust loads about 2.8k tokens when it runs. Until then it costs about 27 tokens; SKILL.md has 526 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~27
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • NoteRuns commands with sudoSKILL.md:45
    pkg.cloudflare.com/cloudflare-main.gpg | sudo tee /usr/share/keyrings/cloudflare-main.gpg >/dev/null
  • NoteRuns commands with sudoSKILL.md:46
    m/cloudflared $(lsb_release -cs) main" | sudo tee /etc/apt/sources.list.d/cloudflared.list
  • NoteRuns commands with sudoSKILL.md:47
    sudo apt update && sudo apt install -y cloudflared
  • NoteRuns commands with sudoSKILL.md:114
    sudo cloudflared service install
  • NoteRuns commands with sudoSKILL.md:115
    sudo systemctl enable cloudflared
  • NoteRuns commands with sudoSKILL.md:116
    sudo systemctl start cloudflared
  • WarningLinks to a raw public IP addressSKILL.md:292
    # 1. Install WARP client from https://1.1.1.1
  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:333
    # ~/.ssh/config

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sickn33/agentic-awesome-skills at commit ec02547, republished under its MIT licence (© sickn33). 526 words, ~2,800 tokens.

Download SKILL.mdSave it as .claude/skills/cloudflare-zero-trust/SKILL.md (or your agent's skills folder).
name
cloudflare-zero-trust
description
Protect internal apps with Cloudflare Access, device posture, and Zero Trust policies.
compatibility
Requires the relevant OS/platform tooling and privileged access where noted. Docs-only; helper scripts and templates not bundled.
category
devops
risk
critical
source
https://github.com/BagelHole/DevOps-Security-Agent-Skills
source_repo
BagelHole/DevOps-Security-Agent-Skills
source_type
community
date_added
2026-09-20
license
MIT
license_source
https://github.com/BagelHole/DevOps-Security-Agent-Skills/blob/main/LICENSE
metadata.author
devops-skills
metadata.version
1.0

Cloudflare Zero Trust

Secure access to internal services without VPNs using Cloudflare's Zero Trust platform (Access, Tunnel, Gateway, and WARP).

When to Use

  • Replacing VPN access to internal web applications, SSH, or RDP.
  • Enforcing identity-aware access policies on internal tools (dashboards, admin panels).
  • Exposing on-premises or private-network services securely to remote teams.
  • Filtering DNS traffic to block malware, phishing, and shadow IT.
  • Enforcing device posture checks (managed devices, OS version, disk encryption).

Prerequisites

  • Cloudflare account with Zero Trust plan (free tier supports up to 50 users).
  • A domain on Cloudflare (for Access application hostnames).
  • Identity provider configured (Google Workspace, Okta, Azure AD/Entra ID, GitHub).
  • cloudflared CLI installed on the server hosting internal services.
bash
# Install cloudflared
# macOS
brew install cloudflared

# Debian/Ubuntu
curl -fsSL https://pkg.cloudflare.com/cloudflare-main.gpg | sudo tee /usr/share/keyrings/cloudflare-main.gpg >/dev/null
echo "deb [signed-by=/usr/share/keyrings/cloudflare-main.gpg] https://pkg.cloudflare.com/cloudflared $(lsb_release -cs) main" | sudo tee /etc/apt/sources.list.d/cloudflared.list
sudo apt update && sudo apt install -y cloudflared

# Docker
docker pull cloudflare/cloudflared:latest

Cloudflare Tunnel Setup

Tunnels create encrypted outbound connections from your infrastructure to Cloudflare's edge, eliminating the need to open inbound ports.

Create and Configure a Tunnel
bash
# Authenticate with Cloudflare
cloudflared tunnel login

# Create a named tunnel
cloudflared tunnel create internal-apps

# This creates credentials at ~/.cloudflared/<TUNNEL_ID>.json

# List tunnels
cloudflared tunnel list

# Route DNS to the tunnel (creates a CNAME record)
cloudflared tunnel route dns internal-apps grafana.example.com
cloudflared tunnel route dns internal-apps wiki.example.com
cloudflared tunnel route dns internal-apps ssh.example.com
Tunnel Configuration File
yaml
# ~/.cloudflared/config.yml
tunnel: <TUNNEL_ID>
credentials-file: /home/deploy/.cloudflared/<TUNNEL_ID>.json

ingress:
  # Grafana dashboard
  - hostname: grafana.example.com
    service: http://localhost:3000

  # Internal wiki
  - hostname: wiki.example.com
    service: http://localhost:8080
    originRequest:
      noTLSVerify: true

  # SSH access via browser
  - hostname: ssh.example.com
    service: ssh://localhost:22

  # Private network access (CIDR routing)
  - hostname: internal.example.com
    service: http://10.0.0.0/24

  # Catch-all — required as the last rule
  - service: http_status:404
Run the Tunnel
bash
# Run in foreground (for testing)
cloudflared tunnel run internal-apps

# Install as a systemd service
sudo cloudflared service install
sudo systemctl enable cloudflared
sudo systemctl start cloudflared

# Or run via Docker
docker run -d --name cloudflared \
  --restart unless-stopped \
  -v /home/deploy/.cloudflared:/etc/cloudflared \
  cloudflare/cloudflared:latest \
  tunnel run internal-apps
Docker Compose with Tunnel
yaml
# docker-compose.yml
version: "3.8"
services:
  cloudflared:
    image: cloudflare/cloudflared:latest
    restart: unless-stopped
    command: tunnel run
    environment:
      - TUNNEL_TOKEN=${TUNNEL_TOKEN}
    networks:
      - internal

  grafana:
    image: grafana/grafana:latest
    networks:
      - internal

  wiki:
    image: requarks/wiki:2
    networks:
      - internal

networks:
  internal:
    driver: bridge

Access Policies

Access policies control who can reach applications behind Cloudflare.

Create an Access Application
bash
# Via API — create a self-hosted application
curl -X POST "https://api.cloudflare.com/client/v4/accounts/$ACCOUNT_ID/access/apps" \
  -H "Authorization: Bearer $CF_API_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "name": "Grafana",
    "domain": "grafana.example.com",
    "type": "self_hosted",
    "session_duration": "12h",
    "auto_redirect_to_identity": true,
    "allowed_idps": ["<IDP_UUID>"]
  }'
Policy Types and Examples
bash
# Allow policy — members of the engineering group
curl -X POST "https://api.cloudflare.com/client/v4/accounts/$ACCOUNT_ID/access/apps/<APP_ID>/policies" \
  -H "Authorization: Bearer $CF_API_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "name": "Engineering Team",
    "decision": "allow",
    "include": [
      { "group": { "id": "<GROUP_UUID>" } }
    ],
    "require": [
      { "login_method": { "id": "<MFA_METHOD_UUID>" } }
    ]
  }'
Common Policy Patterns
PatternInclude RuleRequire Rule
All employeesEmail domain @company.com-
Engineering onlyAccess Group "Engineering"MFA
Contractors (time-limited)Email listDevice posture
CI/CD automationService token-
External partnersSpecific emailsCountry check
Service Tokens for Automation
bash
# Create a service token for CI/CD
curl -X POST "https://api.cloudflare.com/client/v4/accounts/$ACCOUNT_ID/access/service_tokens" \
  -H "Authorization: Bearer $CF_API_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"name": "github-actions-deploy"}'

# Response includes Client ID and Client Secret
# Use in CI with headers:
# CF-Access-Client-Id: <CLIENT_ID>
# CF-Access-Client-Secret: <CLIENT_SECRET>
bash
# Use service token in CI/CD
curl -H "CF-Access-Client-Id: $CF_CLIENT_ID" \
     -H "CF-Access-Client-Secret: $CF_CLIENT_SECRET" \
     https://grafana.example.com/api/health

Device Posture Checks

Enforce endpoint requirements before granting access.

Configure Posture Checks (Dashboard)
  1. Go to Settings > WARP Client > Device posture.
  2. Add checks:
    • Disk encryption: Require FileVault (macOS) or BitLocker (Windows).
    • OS version: Minimum macOS 14.0 or Windows 11.
    • Firewall: Ensure host firewall is enabled.
    • Crowdstrike/SentinelOne: Verify EDR agent is running.
  3. Reference posture checks in Access policies under Require rules.

Gateway DNS Filtering

Block malicious domains and enforce acceptable use policies at the DNS level.

DNS Locations
bash
# Configure DNS endpoints for offices or networks
# Dashboard: Gateway > DNS Locations > Add a location
# Assign the Gateway DNS IPs to your network's DNS resolver:
# IPv4: 172.64.36.1, 172.64.36.2
# IPv6: 2606:4700:4700::1111
# DoH: https://<UNIQUE_ID>.cloudflare-gateway.com/dns-query
DNS Policies
bash
# Create a DNS policy to block malware and phishing
curl -X POST "https://api.cloudflare.com/client/v4/accounts/$ACCOUNT_ID/gateway/rules" \
  -H "Authorization: Bearer $CF_API_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "name": "Block Security Threats",
    "enabled": true,
    "action": "block",
    "traffic": "any(dns.security_category[*] in {80 83 131 134 151 153})",
    "filters": ["dns"]
  }'
Common DNS Policy Rules
Rule NameTraffic ExpressionAction
Block malwareany(dns.security_category[*] in {80 83})Block
Block phishingany(dns.security_category[*] in {131 134})Block
Block social mediaany(dns.content_category[*] in {75})Block
Allow exceptionsdns.fqdn == "allowed.example.com"Allow
Show full SKILL.md (203 more words)Show less

WARP Client Deployment

Deploy the Cloudflare WARP client to route traffic through Gateway.

bash
# MDM deployment — macOS configuration profile
# Use Cloudflare's managed deployment:
# Dashboard: Settings > WARP Client > Device enrollment

# Manual enrollment
# 1. Install WARP client from https://1.1.1.1
# 2. Click gear icon > Account > Login with Cloudflare Zero Trust
# 3. Enter your team name (from Settings > General)

# Verify WARP is connected
curl https://connectivity.cloudflare.com/cdn-cgi/trace
# Look for: warp=on
WARP Split Tunnels
bash
# Configure split tunnels to exclude certain traffic from WARP
# Dashboard: Settings > WARP Client > Device settings > Split Tunnels

# Exclude mode (default): WARP handles everything except listed IPs
# Include mode: WARP only handles listed IPs/domains

# Common exclusions:
# - Local network: 192.168.0.0/16, 10.0.0.0/8
# - Video conferencing: zoom.us, *.teams.microsoft.com
# - Printer subnets

SSH and Browser-Based Terminal

yaml
# In cloudflared config.yml — expose SSH via browser rendering
ingress:
  - hostname: ssh.example.com
    service: ssh://localhost:22
bash
# Users access ssh.example.com in their browser
# Cloudflare renders an in-browser terminal after Access authentication

# Or use cloudflared on the client side for native SSH
cloudflared access ssh --hostname ssh.example.com

# Add to SSH config for seamless access
# ~/.ssh/config
# Host ssh.example.com
#   ProxyCommand /usr/local/bin/cloudflared access ssh --hostname %h

Troubleshooting

SymptomCauseFix
Tunnel shows ERR in dashboardcloudflared not running or config errorCheck systemctl status cloudflared; validate config YAML
Access returns 403 despite correct identityPolicy order or missing require rulePolicies are evaluated top-to-bottom; ensure Allow is above Block
WARP shows "Unable to connect"Team name wrong or enrollment disabledVerify team name in Settings > General; check enrollment permissions
Service token auth failsToken expired or wrong headersRegenerate token; use both CF-Access-Client-Id and CF-Access-Client-Secret
DNS filtering not blockingClient not using Gateway DNS resolversVerify DNS is set to 172.64.36.1; check WARP is connected
Tunnel latency spikesTunnel running on overloaded hostMonitor cloudflared resource usage; run on dedicated infra
"No healthy origins" errorBackend service is downCheck the service at the configured ingress port; review cloudflared logs
  • cloudflare-workers (cloudflare-workers) - Edge compute behind Access policies
  • dns-management (dns-management) - DNS routing and record management
  • reverse-proxy (reverse-proxy) - Alternative gateway patterns
  • service-mesh (service-mesh) - Internal service-to-service security

Limitations

  • Infrastructure commands can disrupt services: confirm target host/scope and have backups/snapshots before mutating state.
  • Docs-only import: upstream scripts and templates not bundled.

© sickn33, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/cloudflare-zero-trust of sickn33/agentic-awesome-skills.

Open the folder on GitHubat commit ec02547

Used in 2 other repositories

We found 6 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Cloudflare Zero Trust next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cloudflare Zero Trust compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cloudflare Zero Trust this skillsickn33/agentic-awesome-skills47k2 repos~2.8kAutomated safety check: WarnMIT
Cloudflarehodgef/apiker1277 repos~2.2kAutomated safety check: PassMIT
Nextjs On Cloudflarecloudflare/skills3k2 repos~678Automated safety check: PassApache-2.0
Cloudflaredmmulroy/cloudflare-skill727—~1.6kAutomated safety check: PassMIT
Devopsnicepkg/auto-company1922 repos~814Automated safety check: PassMIT
Prepare Cloudflare Production DeploymentLubomirGeorgiev/cloudflare-workers-nextjs-saas-template786—~5.9kAutomated safety check: NotesMIT

Similar skills

  • Cloudflare

    hodgef/apiker

    Comprehensive Cloudflare platform skill covering Workers, Pages, storage (KV, D1, R2), AI (Workers AI, Vectorize, Agents SDK), feature flags (Flagship), networking (Tunnel, Spectrum), security (WAF…

    127 GitHub starsUsed in 7 repos~2.2k tokens
    DevOps & CloudAuto-check passed
  • Nextjs On Cloudflare

    cloudflare/skills

    Official

    Build, migrate, and deploy Next.js apps on Cloudflare Workers with vinext.

    3k GitHub starsUsed in 2 repos~678 tokens
    DevOps & CloudAuto-check passed
  • Cloudflare

    dmmulroy/cloudflare-skill

    Comprehensive Cloudflare platform skill covering Workers, Pages, storage (KV, D1, R2), AI (Workers AI, Vectorize, Agents SDK), networking (Tunnel, Spectrum), security (WAF, DDoS), and…

    727 GitHub stars~1.6k tokensUpdated 8 mo ago
    DevOps & CloudAuto-check passed
  • Devops

    nicepkg/auto-company

    Deploy to Cloudflare (Workers, R2, D1), Docker, GCP (Cloud Run, GKE), Kubernetes (kubectl, Helm).

    192 GitHub starsUsed in 2 repos~814 tokens
    DevOps & CloudAuto-check passed
  • Prepare Cloudflare Production Deployment

    LubomirGeorgiev/cloudflare-workers-nextjs-saas-template

    Source-of-truth runbook for preparing this Vinext Cloudflare Workers SaaS template for production deployment.

    786 GitHub stars~5.9k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Workers Best Practices

    cloudflare/skills

    Official

    Cloudflare Workers best practices for production applications.

    3k GitHub starsUsed in 2 repos~1.4k tokens
    DevOps & CloudAuto-check passed

More from sickn33/agentic-awesome-skills

All 1,354 skills in this repo
  • Liuguang Banlan UI

    sickn33/agentic-awesome-skills

    Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • User Thoughts Memory

    sickn33/agentic-awesome-skills

    Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Using LWC Memory and Graphs

    sickn33/agentic-awesome-skills

    Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.

    47k GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Find Complementary Founders

    sickn33/agentic-awesome-skills

    Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.

    47k GitHub starsUsed in 1 repo~4.8k tokens
    Auto-check passed
  • Cline Pilot

    sickn33/agentic-awesome-skills

    Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.

    47k GitHub starsUsed in 1 repo~4.6k tokens
    Auto-check passed
  • Content Creator

    sickn33/agentic-awesome-skills

    Drafts and reviews audience-specific content from supplied brand examples, with local scripts for brand voice and SEO diagnostics, channel templates and a content calendar.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed

Works with

Categories

Questions about Cloudflare Zero Trust

What does Cloudflare Zero Trust do?

Protect internal apps with Cloudflare Access, device posture, and Zero Trust policies. Cloudflare Zero Trust is an agent skill from sickn33/agentic-awesome-skills. Protect internal apps with Cloudflare Access, device posture, and Zero Trust policies.

When should I use Cloudflare Zero Trust?

Cloudflare Zero Trust fits situations like: devOps & Cloud work in your project.

How do I install Cloudflare Zero Trust in Claude Code?

Run `npx skills add sickn33/agentic-awesome-skills --skill cloudflare-zero-trust -a claude-code`. Or copy the skill folder (skills/cloudflare-zero-trust in sickn33/agentic-awesome-skills) into .claude/skills/cloudflare-zero-trust in your project. Claude Code loads it when a task matches its description.

How do I install Cloudflare Zero Trust in Codex?

Run `npx skills add sickn33/agentic-awesome-skills --skill cloudflare-zero-trust -a codex`. Or copy the skill folder (skills/cloudflare-zero-trust in sickn33/agentic-awesome-skills) into .agents/skills/cloudflare-zero-trust in your project. Codex loads it when a task matches its description.

Can I use Cloudflare Zero Trust in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill cloudflare-zero-trust -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cloudflare-zero-trust, .gemini/skills/cloudflare-zero-trust, .github/skills/cloudflare-zero-trust and .opencode/skills/cloudflare-zero-trust in your project.

What does Cloudflare Zero Trust need to run?

Going by SKILL.md and its folder, Cloudflare Zero Trust needs the command-line tools its instructions call (cloudflared, curl, apt, docker and brew) and credentials named CF_API_TOKEN, TUNNEL_TOKEN, CLIENT_SECRET and CF_CLIENT_SECRET. Our summary lists: Docker; A credential in TUNNEL_TOKEN; A credential in CF_API_TOKEN. Compatibility (from SKILL.md): Requires the relevant OS/platform tooling and privileged access where noted. Docs-only; helper scripts and templates not bundled..

Does Cloudflare Zero Trust access the network?

SKILL.md names 3 domains. In commands or code: api.cloudflare.com, pkg.cloudflare.com and connectivity.cloudflare.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.

Is Cloudflare Zero Trust safe to install?

Our automated static check of SKILL.md flagged 2 warning(s): links to a raw public ip address; mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.

What licence does Cloudflare Zero Trust use?

Cloudflare Zero Trust is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cloudflare Zero Trust use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Cloudflare Zero Trust?

Skills that share tags, products or a category with Cloudflare Zero Trust: Cloudflare (hodgef/apiker, 127 stars), Nextjs On Cloudflare (cloudflare/skills, 3k stars), Cloudflare (dmmulroy/cloudflare-skill, 727 stars) and Devops (nicepkg/auto-company, 192 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cloudflare Zero Trust?

sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,343 GitHub stars. The repository holds 1,354 skills in this directory. The repository was last updated on October 7, 2026.

Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.