Agent Skill · Cloudflare

cloudflare-one

Guides Cloudflare One Zero Trust and SASE work across Access, Gateway, WARP, Tunnel, Cloudflare WAN, DLP, CASB, device posture, and identity. Use when designing, configuring, troubleshooting, or reviewing Cloudflare One deployments. Retrieval-first: use current Cloudflare docs/API schemas instead of embedded product docs.

Provider: Cloudflare Path in repo: skills/cloudflare-one/SKILL.md

Skill body

Cloudflare One

Before citing limits, settings, API fields, category IDs, or exact UI paths, retrieve current information from the Cloudflare One docs, the Cloudflare docs MCP server, or the Cloudflare API schema.

Workflow

  1. Classify the ask: architecture, configuration, troubleshooting, migration, or review.
  2. Gather context: account ID, users/sites/apps, identity provider, SCIM/group sync, device management, traffic path, compliance constraints, and rollout blast radius.
  3. Retrieve only the current docs needed for the products involved: Access, Gateway, WARP/device client, Tunnel/Mesh, Cloudflare WAN, DLP, CASB, device posture, or identity.
  4. If account access is available, inspect existing resources before proposing or making changes: Access apps/policies/groups/IdPs, Gateway rules/lists/categories, device profiles/posture checks, tunnels/routes, DNS/resolver settings, and locations/sites.
  5. Propose the change set with prerequisites, validation, and rollback. For risky changes, stage disabled or scoped to a pilot group/site unless the user explicitly asks otherwise.

Assessment Prompts

Use these to avoid jumping straight to configuration. Ask only the prompts relevant to the user’s task.

Architecture and Current State

Access and SaaS Federation

Tunnel and Private Networking

Gateway, TLS, and DLP

CASB, Device Posture, and Risk

Cloudflare WAN / Site Connectivity

Guardrails

Identity and Access

Device Client Deployment

Private Networking

Gateway, TLS, and DLP

CASB, Risk, and Operations

Infrastructure Access

Logs, Analytics, and DEX

Cloudflare WAN / Site Connectivity

Output Defaults

Validation Prompts

API Safety