Revesery
Dashboard
Home
Explore
Groups
Tools
Task
Social Media
VideoBulk VideoProfile PictureSlide ShowSound / AudioUnfollowersDouyin
VideoBulk Video
VideoStoriesBulk VideoProfile PictureSlide ShowUnfollowersStalker CheckSoon
VideoUnfollowers
MP4 · VideoMP3 · Audio
WhatsApp
Profile PictureCover Art & Preview
Profile Picture
Video & Image
Video & Photo
Utilities
AI Chat
Fake SNBTWatermark KTP
TeraboxVidey
Deep Voice CheckerReview Calculator
Surat IzinQR GeneratorSoon
Case ConverterCookie Converter
Request a toolImage ToolsSoonText ToolsSoon
Premium
Soon
Add bookmarks
Revesery
HomeExploreTrendingGroupsContributors
⌘K

Most read

Nothing published yet — type a topic and we’ll dig.
ShareLogin
Back to feed
AR
Alex RuiezExpert
@alex · Sep 23, 2026 · 4 views
#News

Cloudflare Open-Sources Its Vulnerability Discovery Skill

Your coding agent can write code quickly, but can it tell you where that code is weak? Cloudflare just open-sourced the skill behind its own vulnerability discovery harness, and the way it checks its own findings is the part worth reading about.

The skill runs separate agents through three stages — recon, hunting, then verification — so a suspected hole gets a second look before it ever lands in your report.

Cloudflare Open-Sources Its Vulnerability Discovery Skill

What Happened

Cloudflare open-sourced the skill that seeded its vulnerability discovery harness. It works in stages: one set of agents does recon, another hunts for security holes, and a final pass verifies each finding before it is handed over.

Splitting the job across agents is the point: the agent looking for problems is not the agent deciding whether a problem is real.

The post does not name the repository and does not include a link, so there is nothing to download from it directly. If you want the code, you will have to find Cloudflare's release yourself.

Why It Matters

Automated scanning has a noise problem. A tool that flags everything costs you more time than it saves — and that gets worse when the tool is an AI agent that sounds confident about every guess.

Putting a verification step between the hunt and the report is a simple fix: a second agent has to agree before anything gets called a vulnerability. Whether that holds up on real code is the open question, but it is the right place to spend effort.

Liked Alex Ruiez's share? Revesery is where people swap what they're actually building.

Join with Google
Be the first to sayBe first

Does this still work?

Nobody's checked yet

Sign in to tell everyone how it went.

Continue with Google

Be the first — one tap saves the next person an hour.

It takes 3 reports in 30 days to set the status.

Comments

Join the conversation — sign in to comment.

Sign In Now

No comments yet — start the conversation!

More shares you might like

AIZCode Reportedly Packaged Whole Workspaces, Git History IncludedAlex Ruiez · 1h · 4 viewsToolsBug Bounty: Why Business Logic Flaws Pay More Than Most CVEsAlex Ruiez · 1h · 4 viewsNewsLogic Flaws Cause More Damage Than Memory Corruption BugsAlex Ruiez · 1h · 5 viewsAIClaude Opus 5.5 Turns One Prompt Into a 30-Second FilmAlex Ruiez · 1h · 5 viewsAIHow to Make Affiliate Videos With Free Motion Control AIAlex Ruiez · 1h · 5 viewsToolsHow to Pick Your First Amazon Affiliate NicheAlex Ruiez · 13h · 13 views

Site footer

Revesery

Empowering people to share valuable insights, discover hidden information, and connect with an amazing community of learners and experts.

  • 393Members
  • 526Shares published
  • 0Online now

Explore

  • Explore shares
  • Trending now
  • Top contributors

Company

  • About us
  • Editorial policy
  • Contact
  • Advertise with us
  • System status
© 2026 Revesery
  • Privacy
  • Terms
  • Trust & Safety
  • DMCA
HomeExploreShareToolsProfile
LiveAKakunfadiljoined Revesery· 3 hours ago