Cloudflare
hodgef/apiker
Comprehensive Cloudflare platform skill covering Workers, Pages, storage (KV, D1, R2), AI (Workers AI, Vectorize, Agents SDK), feature flags (Flagship), networking (Tunnel, Spectrum), security (WAF…
Protect internal apps with Cloudflare Access, device posture, and Zero Trust policies.
The automated check flagged lines worth reading first. See the safety section below.
$ npx skills add sickn33/agentic-awesome-skills --skill cloudflare-zero-trust -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install sickn33/agentic-awesome-skills cloudflare-zero-trust --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cloudflare-zero-trust .claude/skills/cloudflare-zero-trust && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "cloudflare-zero-trust" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/cloudflare-zero-trust into .claude/skills/cloudflare-zero-trust/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloudflare-zero-trust", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/cloudflare-zero-trustType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add sickn33/agentic-awesome-skills --skill cloudflare-zero-trust -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install sickn33/agentic-awesome-skills cloudflare-zero-trust --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/cloudflare-zero-trust .agents/skills/cloudflare-zero-trust && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "cloudflare-zero-trust" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/cloudflare-zero-trust into .agents/skills/cloudflare-zero-trust/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloudflare-zero-trust", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add sickn33/agentic-awesome-skills --skill cloudflare-zero-trust -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install sickn33/agentic-awesome-skills cloudflare-zero-trust --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/cloudflare-zero-trust .cursor/skills/cloudflare-zero-trust && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "cloudflare-zero-trust" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/cloudflare-zero-trust into .cursor/skills/cloudflare-zero-trust/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloudflare-zero-trust", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/sickn33/agentic-awesome-skills.git --path skills/cloudflare-zero-trust--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add sickn33/agentic-awesome-skills --skill cloudflare-zero-trust -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install sickn33/agentic-awesome-skills cloudflare-zero-trust --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/cloudflare-zero-trust .gemini/skills/cloudflare-zero-trust && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "cloudflare-zero-trust" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/cloudflare-zero-trust into .gemini/skills/cloudflare-zero-trust/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloudflare-zero-trust", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install sickn33/agentic-awesome-skills cloudflare-zero-trustInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add sickn33/agentic-awesome-skills --skill cloudflare-zero-trust -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/cloudflare-zero-trust .github/skills/cloudflare-zero-trust && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "cloudflare-zero-trust" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/cloudflare-zero-trust into .github/skills/cloudflare-zero-trust/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloudflare-zero-trust", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add sickn33/agentic-awesome-skills --skill cloudflare-zero-trust -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install sickn33/agentic-awesome-skills cloudflare-zero-trust --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/cloudflare-zero-trust .opencode/skills/cloudflare-zero-trust && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "cloudflare-zero-trust" agent skill from https://github.com/sickn33/agentic-awesome-skills/tree/main/skills/cloudflare-zero-trust into .opencode/skills/cloudflare-zero-trust/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "cloudflare-zero-trust", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
cloudflare-zero-trustProtect internal apps with Cloudflare Access, device posture, and Zero Trust policies.
Cloudflare Zero Trust is an agent skill from sickn33/agentic-awesome-skills. Protect internal apps with Cloudflare Access, device posture, and Zero Trust policies.
Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Requires the relevant OS/platform tooling and privileged access where noted. Docs-only; helper scripts and templates not bundled.
It sits in DevOps & Cloud. It works with Cloudflare. The repository describes itself as: AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 2,400+ agentic skills. Includes… The licence is MIT.
3 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit ec02547. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
cloudflaredcurlaptdockerbrewFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
api.cloudflare.compkg.cloudflare.comconnectivity.cloudflare.comFrom URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
CF_API_TOKENTUNNEL_TOKENCLIENT_SECRETCF_CLIENT_SECRETFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Requires the relevant OS/platform tooling and privileged access where noted. Docs-only; helper scripts and templates not bundled.
From compatibility in the SKILL.md frontmatter.
Cloudflare Zero Trust loads about 2.8k tokens when it runs. Until then it costs about 27 tokens; SKILL.md has 526 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found patterns that need a careful read before installing.
pkg.cloudflare.com/cloudflare-main.gpg | sudo tee /usr/share/keyrings/cloudflare-main.gpg >/dev/nullm/cloudflared $(lsb_release -cs) main" | sudo tee /etc/apt/sources.list.d/cloudflared.listsudo apt update && sudo apt install -y cloudflaredsudo cloudflared service installsudo systemctl enable cloudflaredsudo systemctl start cloudflared# 1. Install WARP client from https://1.1.1.1# ~/.ssh/configAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from sickn33/agentic-awesome-skills at commit ec02547, republished under its MIT licence (© sickn33). 526 words, ~2,800 tokens.
.claude/skills/cloudflare-zero-trust/SKILL.md (or your agent's skills folder).Secure access to internal services without VPNs using Cloudflare's Zero Trust platform (Access, Tunnel, Gateway, and WARP).
cloudflared CLI installed on the server hosting internal services.# Install cloudflared
# macOS
brew install cloudflared
# Debian/Ubuntu
curl -fsSL https://pkg.cloudflare.com/cloudflare-main.gpg | sudo tee /usr/share/keyrings/cloudflare-main.gpg >/dev/null
echo "deb [signed-by=/usr/share/keyrings/cloudflare-main.gpg] https://pkg.cloudflare.com/cloudflared $(lsb_release -cs) main" | sudo tee /etc/apt/sources.list.d/cloudflared.list
sudo apt update && sudo apt install -y cloudflared
# Docker
docker pull cloudflare/cloudflared:latestTunnels create encrypted outbound connections from your infrastructure to Cloudflare's edge, eliminating the need to open inbound ports.
# Authenticate with Cloudflare
cloudflared tunnel login
# Create a named tunnel
cloudflared tunnel create internal-apps
# This creates credentials at ~/.cloudflared/<TUNNEL_ID>.json
# List tunnels
cloudflared tunnel list
# Route DNS to the tunnel (creates a CNAME record)
cloudflared tunnel route dns internal-apps grafana.example.com
cloudflared tunnel route dns internal-apps wiki.example.com
cloudflared tunnel route dns internal-apps ssh.example.com# ~/.cloudflared/config.yml
tunnel: <TUNNEL_ID>
credentials-file: /home/deploy/.cloudflared/<TUNNEL_ID>.json
ingress:
# Grafana dashboard
- hostname: grafana.example.com
service: http://localhost:3000
# Internal wiki
- hostname: wiki.example.com
service: http://localhost:8080
originRequest:
noTLSVerify: true
# SSH access via browser
- hostname: ssh.example.com
service: ssh://localhost:22
# Private network access (CIDR routing)
- hostname: internal.example.com
service: http://10.0.0.0/24
# Catch-all — required as the last rule
- service: http_status:404# Run in foreground (for testing)
cloudflared tunnel run internal-apps
# Install as a systemd service
sudo cloudflared service install
sudo systemctl enable cloudflared
sudo systemctl start cloudflared
# Or run via Docker
docker run -d --name cloudflared \
--restart unless-stopped \
-v /home/deploy/.cloudflared:/etc/cloudflared \
cloudflare/cloudflared:latest \
tunnel run internal-apps# docker-compose.yml
version: "3.8"
services:
cloudflared:
image: cloudflare/cloudflared:latest
restart: unless-stopped
command: tunnel run
environment:
- TUNNEL_TOKEN=${TUNNEL_TOKEN}
networks:
- internal
grafana:
image: grafana/grafana:latest
networks:
- internal
wiki:
image: requarks/wiki:2
networks:
- internal
networks:
internal:
driver: bridgeAccess policies control who can reach applications behind Cloudflare.
# Via API — create a self-hosted application
curl -X POST "https://api.cloudflare.com/client/v4/accounts/$ACCOUNT_ID/access/apps" \
-H "Authorization: Bearer $CF_API_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"name": "Grafana",
"domain": "grafana.example.com",
"type": "self_hosted",
"session_duration": "12h",
"auto_redirect_to_identity": true,
"allowed_idps": ["<IDP_UUID>"]
}'# Allow policy — members of the engineering group
curl -X POST "https://api.cloudflare.com/client/v4/accounts/$ACCOUNT_ID/access/apps/<APP_ID>/policies" \
-H "Authorization: Bearer $CF_API_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"name": "Engineering Team",
"decision": "allow",
"include": [
{ "group": { "id": "<GROUP_UUID>" } }
],
"require": [
{ "login_method": { "id": "<MFA_METHOD_UUID>" } }
]
}'| Pattern | Include Rule | Require Rule |
|---|---|---|
| All employees | Email domain @company.com | - |
| Engineering only | Access Group "Engineering" | MFA |
| Contractors (time-limited) | Email list | Device posture |
| CI/CD automation | Service token | - |
| External partners | Specific emails | Country check |
# Create a service token for CI/CD
curl -X POST "https://api.cloudflare.com/client/v4/accounts/$ACCOUNT_ID/access/service_tokens" \
-H "Authorization: Bearer $CF_API_TOKEN" \
-H "Content-Type: application/json" \
-d '{"name": "github-actions-deploy"}'
# Response includes Client ID and Client Secret
# Use in CI with headers:
# CF-Access-Client-Id: <CLIENT_ID>
# CF-Access-Client-Secret: <CLIENT_SECRET># Use service token in CI/CD
curl -H "CF-Access-Client-Id: $CF_CLIENT_ID" \
-H "CF-Access-Client-Secret: $CF_CLIENT_SECRET" \
https://grafana.example.com/api/healthEnforce endpoint requirements before granting access.
Block malicious domains and enforce acceptable use policies at the DNS level.
# Configure DNS endpoints for offices or networks
# Dashboard: Gateway > DNS Locations > Add a location
# Assign the Gateway DNS IPs to your network's DNS resolver:
# IPv4: 172.64.36.1, 172.64.36.2
# IPv6: 2606:4700:4700::1111
# DoH: https://<UNIQUE_ID>.cloudflare-gateway.com/dns-query# Create a DNS policy to block malware and phishing
curl -X POST "https://api.cloudflare.com/client/v4/accounts/$ACCOUNT_ID/gateway/rules" \
-H "Authorization: Bearer $CF_API_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"name": "Block Security Threats",
"enabled": true,
"action": "block",
"traffic": "any(dns.security_category[*] in {80 83 131 134 151 153})",
"filters": ["dns"]
}'| Rule Name | Traffic Expression | Action |
|---|---|---|
| Block malware | any(dns.security_category[*] in {80 83}) | Block |
| Block phishing | any(dns.security_category[*] in {131 134}) | Block |
| Block social media | any(dns.content_category[*] in {75}) | Block |
| Allow exceptions | dns.fqdn == "allowed.example.com" | Allow |
Deploy the Cloudflare WARP client to route traffic through Gateway.
# MDM deployment — macOS configuration profile
# Use Cloudflare's managed deployment:
# Dashboard: Settings > WARP Client > Device enrollment
# Manual enrollment
# 1. Install WARP client from https://1.1.1.1
# 2. Click gear icon > Account > Login with Cloudflare Zero Trust
# 3. Enter your team name (from Settings > General)
# Verify WARP is connected
curl https://connectivity.cloudflare.com/cdn-cgi/trace
# Look for: warp=on# Configure split tunnels to exclude certain traffic from WARP
# Dashboard: Settings > WARP Client > Device settings > Split Tunnels
# Exclude mode (default): WARP handles everything except listed IPs
# Include mode: WARP only handles listed IPs/domains
# Common exclusions:
# - Local network: 192.168.0.0/16, 10.0.0.0/8
# - Video conferencing: zoom.us, *.teams.microsoft.com
# - Printer subnets# In cloudflared config.yml — expose SSH via browser rendering
ingress:
- hostname: ssh.example.com
service: ssh://localhost:22# Users access ssh.example.com in their browser
# Cloudflare renders an in-browser terminal after Access authentication
# Or use cloudflared on the client side for native SSH
cloudflared access ssh --hostname ssh.example.com
# Add to SSH config for seamless access
# ~/.ssh/config
# Host ssh.example.com
# ProxyCommand /usr/local/bin/cloudflared access ssh --hostname %h| Symptom | Cause | Fix |
|---|---|---|
Tunnel shows ERR in dashboard | cloudflared not running or config error | Check systemctl status cloudflared; validate config YAML |
| Access returns 403 despite correct identity | Policy order or missing require rule | Policies are evaluated top-to-bottom; ensure Allow is above Block |
| WARP shows "Unable to connect" | Team name wrong or enrollment disabled | Verify team name in Settings > General; check enrollment permissions |
| Service token auth fails | Token expired or wrong headers | Regenerate token; use both CF-Access-Client-Id and CF-Access-Client-Secret |
| DNS filtering not blocking | Client not using Gateway DNS resolvers | Verify DNS is set to 172.64.36.1; check WARP is connected |
| Tunnel latency spikes | Tunnel running on overloaded host | Monitor cloudflared resource usage; run on dedicated infra |
| "No healthy origins" error | Backend service is down | Check the service at the configured ingress port; review cloudflared logs |
cloudflare-workers) - Edge compute behind Access policiesdns-management) - DNS routing and record managementreverse-proxy) - Alternative gateway patternsservice-mesh) - Internal service-to-service security© sickn33, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/cloudflare-zero-trust of sickn33/agentic-awesome-skills.
Open the folder on GitHubat commit ec02547
We found 6 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.
Cloudflare Zero Trust next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Cloudflare Zero Trust this skillsickn33/agentic-awesome-skills | 47k | 2 repos | ~2.8k | Automated safety check: Warn | MIT | |
| Cloudflarehodgef/apiker | 127 | 7 repos | ~2.2k | Automated safety check: Pass | MIT | |
| Nextjs On Cloudflarecloudflare/skills | 3k | 2 repos | ~678 | Automated safety check: Pass | Apache-2.0 | |
| Cloudflaredmmulroy/cloudflare-skill | 727 | — | ~1.6k | Automated safety check: Pass | MIT | |
| Devopsnicepkg/auto-company | 192 | 2 repos | ~814 | Automated safety check: Pass | MIT | |
| Prepare Cloudflare Production DeploymentLubomirGeorgiev/cloudflare-workers-nextjs-saas-template | 786 | — | ~5.9k | Automated safety check: Notes | MIT |
hodgef/apiker
Comprehensive Cloudflare platform skill covering Workers, Pages, storage (KV, D1, R2), AI (Workers AI, Vectorize, Agents SDK), feature flags (Flagship), networking (Tunnel, Spectrum), security (WAF…
cloudflare/skills
Build, migrate, and deploy Next.js apps on Cloudflare Workers with vinext.
dmmulroy/cloudflare-skill
Comprehensive Cloudflare platform skill covering Workers, Pages, storage (KV, D1, R2), AI (Workers AI, Vectorize, Agents SDK), networking (Tunnel, Spectrum), security (WAF, DDoS), and…
nicepkg/auto-company
Deploy to Cloudflare (Workers, R2, D1), Docker, GCP (Cloud Run, GKE), Kubernetes (kubectl, Helm).
LubomirGeorgiev/cloudflare-workers-nextjs-saas-template
Source-of-truth runbook for preparing this Vinext Cloudflare Workers SaaS template for production deployment.
cloudflare/skills
Cloudflare Workers best practices for production applications.
sickn33/agentic-awesome-skills
Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.
sickn33/agentic-awesome-skills
Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.
sickn33/agentic-awesome-skills
Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.
sickn33/agentic-awesome-skills
Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.
sickn33/agentic-awesome-skills
Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.
sickn33/agentic-awesome-skills
Drafts and reviews audience-specific content from supplied brand examples, with local scripts for brand voice and SEO diagnostics, channel templates and a content calendar.
Works with
Categories
Protect internal apps with Cloudflare Access, device posture, and Zero Trust policies. Cloudflare Zero Trust is an agent skill from sickn33/agentic-awesome-skills. Protect internal apps with Cloudflare Access, device posture, and Zero Trust policies.
Cloudflare Zero Trust fits situations like: devOps & Cloud work in your project.
Run `npx skills add sickn33/agentic-awesome-skills --skill cloudflare-zero-trust -a claude-code`. Or copy the skill folder (skills/cloudflare-zero-trust in sickn33/agentic-awesome-skills) into .claude/skills/cloudflare-zero-trust in your project. Claude Code loads it when a task matches its description.
Run `npx skills add sickn33/agentic-awesome-skills --skill cloudflare-zero-trust -a codex`. Or copy the skill folder (skills/cloudflare-zero-trust in sickn33/agentic-awesome-skills) into .agents/skills/cloudflare-zero-trust in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill cloudflare-zero-trust -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cloudflare-zero-trust, .gemini/skills/cloudflare-zero-trust, .github/skills/cloudflare-zero-trust and .opencode/skills/cloudflare-zero-trust in your project.
Going by SKILL.md and its folder, Cloudflare Zero Trust needs the command-line tools its instructions call (cloudflared, curl, apt, docker and brew) and credentials named CF_API_TOKEN, TUNNEL_TOKEN, CLIENT_SECRET and CF_CLIENT_SECRET. Our summary lists: Docker; A credential in TUNNEL_TOKEN; A credential in CF_API_TOKEN. Compatibility (from SKILL.md): Requires the relevant OS/platform tooling and privileged access where noted. Docs-only; helper scripts and templates not bundled..
SKILL.md names 3 domains. In commands or code: api.cloudflare.com, pkg.cloudflare.com and connectivity.cloudflare.com; the agent is likely to contact these when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md flagged 2 warning(s): links to a raw public ip address; mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way.
Cloudflare Zero Trust is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Cloudflare Zero Trust: Cloudflare (hodgef/apiker, 127 stars), Nextjs On Cloudflare (cloudflare/skills, 3k stars), Cloudflare (dmmulroy/cloudflare-skill, 727 stars) and Devops (nicepkg/auto-company, 192 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,343 GitHub stars. The repository holds 1,354 skills in this directory. The repository was last updated on October 7, 2026.
Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.