Cloudflare One Zero Trust Advisor
Guides agents through designing, configuring, and troubleshooting Cloudflare One.
The skill requires current documentation and architectural context, inspection of existing resources, staged rollouts, explicit rollback, and approval before broad production policies; this reduces overreach and destructive-change risk. Points are deducted because credential handling, log/DLP payload data flows, least-privilege boundaries, isolation, and per-change confirmation for MCP/API actions are not fully specified.
The workflow, product taxonomy, troubleshooting guidance, and validation prompts are generally consistent, with a diagnosable path from logs back to policies, routes, or tunnels. Points are deducted because there are no committed tests or scripts, operation depends on current external docs, MCP, and API availability, and failure feedback for retrieval or abnormal inputs is limited; static calibration caps this at 10.
The name and description clearly target Cloudflare One architecture, configuration, migration, troubleshooting, and review, with task-specific prompts for Access, Gateway, Tunnel, DLP, and identity. Points are deducted because non-fit boundaries, exclusion triggers, and input/output contracts remain underspecified, Chinese-language support is not addressed, and mainland-China reachability of the overseas documentation/MCP dependencies is unverified.
The document has metadata, a workflow, layered topic prompts, guardrails, validation prompts, and output defaults; repository context provides installation guidance and a clear Apache-2.0 license. Points are deducted because the skill lacks its own versioning, changelog, named maintenance owner, explicit update path, dependency troubleshooting, example outputs, and known-limitations section.
For design, configuration review, and troubleshooting, the skill supplies usable context checklists, product responsibility distinctions, validation cases, rollback guidance, and phased rollout advice, completing the core decision-support task. Points are deducted because it is primarily a retrieval and review framework rather than a verified configuration or outcome generator; key facts require re-retrieval and substantial human review remains necessary. Static calibration caps this at 7.
The skill contains many references to Cloudflare primary documentation and requires current API schemas; repository context also shows a Semgrep CI workflow. Points are deducted because there are no committed tests, fixed fixtures, or third-party execution evidence covering the skill's key paths, so conclusions cannot be independently reproduced from static files; static calibration caps this at 5.
- Do not treat product fields, policy ordering, category IDs, or API request bodies in the skill as verified facts; confirm current official documentation, schemas, and account objects first.
- For production policies, TLS inspection, DLP, routing, tunnels, or identity changes, use a scoped pilot with explicit approval and an executable rollback plan.
- Do not send credentials, PSKs, logs, or DLP payloads to unreviewed external tools; the skill does not fully define those data-handling boundaries.
- Verify that Cloudflare documentation and required MCP services are reachable in the target network, and prepare an offline or alternative-reference path if they are not.
What does this skill do, and when should you use it?
This skill focuses on Cloudflare One Access, Gateway, WARP, Tunnel, Cloudflare WAN, DLP, CASB, device posture, and identity. It follows a retrieval-first approach: current Cloudflare documentation, the Cloudflare docs MCP server, or API schemas should be consulted before citing limits, settings, API fields, or exact UI paths. It classifies the task, gathers deployment context, and produces change, validation, and rollback guidance. It is intended for security, networking, and platform teams planning or reviewing Cloudflare One deployments.
Collects context about accounts, users, applications, identity providers, network paths, compliance constraints, and rollout scope for architecture, configuration, troubleshooting, migration, or review tasks; retrieves relevant Cloudflare One documentation or API schemas; inspects existing Access apps and policies, Gateway rules, device settings, tunnels, routes, DNS, and sites when account access is available; and produces prerequisites, resource-level change plans, validation tests, risk controls, and rollback recommendations.
- A security team planning Cloudflare Access and WARP for remote users reaching private applications.
- A networking team designing highly available private connectivity with Cloudflare Tunnel, Mesh, or Cloudflare WAN.
- A platform team configuring Gateway traffic policies, TLS inspection, DLP, or granular SaaS controls.
- An operations team investigating Access denials, Gateway blocks, DNS failures, tunnel errors, or private-route issues.
- An enterprise team reviewing device posture, identity synchronization, CASB, user risk, and staged rollout plans.
What are this skill's strengths and limitations?
- Covers major Cloudflare One products and common deployment patterns.
- Uses current documentation and API schemas instead of relying solely on embedded product knowledge.
- Includes architecture assessment, validation, pilot rollout, log-based troubleshooting, and rollback guidance.
- Provides concrete guardrails for identity sync, split tunneling, private DNS, TLS inspection, and policy precedence.
- Precise configuration depends on access to current Cloudflare documentation, API schemas, or MCP information.
- Inspection of account resources and any actual changes depend on available account access.
- The source shows no supporting scripts, automated test suite, or standalone CLI.
- Its scope is Cloudflare One; it should not be treated as the repository’s broader Workers, Agents SDK, or storage-development skill.
How do you install this skill?
The repository is a collection of 11 skills. Install the collection with npx skills add https://github.com/cloudflare/skills, or clone the repository and copy skills/cloudflare-one into the directory used by your agent, such as ~/.codex/skills/ for OpenAI Codex or ~/.claude/skills/ for Claude Code. The source does not provide a separate installation command for this individual skill.
How do you use this skill?
After installation, ask a natural-language Cloudflare One question, for example: “Review our Cloudflare Tunnel and WARP private-application architecture and provide validation and rollback steps.” The skill classifies the request, gathers relevant context, and retrieves current documentation. The source does not document a dedicated slash command, script, or test command for this skill.
How does this skill compare with similar options?
This is guidance for agents, not a replacement for Cloudflare One services or an account-management tool. It helps distinguish responsibilities and choose among Cloudflare One components: Access authorizes applications, Gateway inspects traffic, and private connectivity may use Tunnel, Mesh, or Cloudflare WAN.