跳到主要内容
知仓学习社ZHICANG

openai-cloudflare-deploy

Deploy applications and infrastructure to Cloudflare using Workers, Pages, and related platform

读凭据执行命令联网写文件读文件严重 17 · 高危 0trailofbits/skills-curated

它会碰到什么

扫了多少308 个文本文件,1299 KB
它会碰到什么读凭据执行命令联网写文件读文件
命中总数604 处
命中统计严重 17 · 高 0 · 中 1 · 低 31
逐条看命中(17 条严重或高危)
  • 严重 references/api/configuration.md:15cred-paths
    ### .env File Pattern
  • 严重 references/api/configuration.md:18cred-paths
    # .env (add to .gitignore)
  • 严重 references/argo-smart-routing/configuration.md:114cred-paths
    # .env
  • 严重 references/d1/README.md:81instruction-harmful-additive
    | Read replicas | Not available | Yes (paid add-on) |
  • 严重 references/r2-sql/configuration.md:78cred-paths
    Or create `.env` file in project directory:
  • 严重 references/r2-sql/configuration.md:84cred-paths
    Wrangler automatically loads `.env` file when running commands.
  • 严重 references/r2-sql/gotchas.md:100cred-paths
    # Or .env file
  • 严重 references/r2-sql/gotchas.md:101cred-paths
    echo "WRANGLER_R2_SQL_AUTH_TOKEN=<your-token>" > .env
  • 严重 references/sandbox/patterns.md:40exec-pipe-to-shell
    await sandbox.exec('curl -fsSL https://code-server.dev/install.sh | sh');
  • 严重 references/tunnel/patterns.md:21cred-paths
    - ./credentials.json:/etc/cloudflared/credentials.json:ro
  • 严重 references/tunnel/patterns.md:21cred-paths
    - ./credentials.json:/etc/cloudflared/credentials.json:ro
  • 严重 references/tunnel/patterns.md:184persistence
    systemctl start cloudflared && systemctl enable cloudflared
  • 严重 references/turn/configuration.md:8cred-paths
    # .env
  • 严重 references/turnstile/gotchas.md:205cred-paths
    **Solution:** Check .env and verify loading.
  • 严重 references/turnstile/gotchas.md:207cred-paths
    # .env
  • 严重 references/web-analytics/patterns.md:70cred-paths
    // .env.production: production token
  • 严重 references/web-analytics/patterns.md:71cred-paths
    // .env.staging: staging token (or empty to disable)

这一栏是扫描器报的事实,不是结论。命中多不等于有毒(安全工具、规则库、示例脚本本来就会包含危险写法),命中少也不等于干净。它和你手上的凭据、文件、网络有什么关系,需要你自己看。

技能内容

Cloudflare Deploy

Consolidated skill for building on the Cloudflare platform. Use decision trees below to find the right product, then load detailed references.

Prerequisites

  • The deployment might take a few minutes. Use appropriate timeout values.

Authentication (Required Before Deploy)

Verify auth before wrangler deploy, wrangler pages deploy, or npm run deploy:

npx wrangler whoami    # Shows account if authenticated

Not authenticated? → references/wrangler/auth.md

  • Interactive/local: wrangler login (one-time OAuth)
  • CI/CD: Set CLOUDFLARE_API_TOKEN env var

Quick Decision Trees

"I need to run code"

Need to run code?
├─ Serverless functions at the edge → workers/
├─ Full-stack web app with Git deploys → pages/
├─ Stateful coordination/real-time → durable-objects/
├─ Long-running multi-step jobs → workflows/
├─ Run containers → containers/
├─ Multi-tenant (customers deploy code) → workers-for-platforms/
├─ Scheduled tasks (cron) → cron-triggers/
├─ Lightweight edge logic (modify HTTP) → snippets/
├─ Process Worker execution events (logs/observability) → tail-workers/
└─ Optimize latency to backend infrastructure → smart-placement/

"I need to store data"

Need storage?
├─ Key-value (config, sessions, cache) → kv/
├─ Relational SQL → d1/ (SQLite) or hyperdrive/ (existing Postgres/MySQL)
├─ Object/file storage (S3-compatible) → r2/
├─ Message queue (async processing) → queues/
├─ Vector embeddings (AI/semantic search) → vectorize/
├─ Strongly-consistent per-entity state → durable-objects/ (DO storage)
├─ Secrets management → secrets-store/
├─ Streaming ETL to R2 → pipelines/
└─ Persistent cache (long-term retention) → cache-reserve/

"I need AI/ML"

Need AI?
├─ Run inference (LLMs, embeddings, images) → workers-ai/
├─ Vector database for RAG/search → vectorize/
├─ Build stateful AI agents → agents-sdk/
├─ Gateway for any AI provider (caching, routing) → ai-gateway/
└─ AI-powered search widget → ai-search/

"I need networking/connectivity"

Need networking?
├─ Expose local service to internet → tunnel/
├─ TCP/UDP proxy (non-HTTP) → spectrum/
├─ WebRTC TURN server → turn/
├─ Private network connectivity → network-interconnect/
├─ Optimize routing → argo-smart-routing/
├─ Optimize latency to backend (not user) → smart-placement/
└─ Real-time video/audio → realtimekit/ or realtime-sfu/

"I need security"

Need security?
├─ Web Application Firewall → waf/
├─ DDoS protection → ddos/
├─ Bot detection/management → bot-management/
├─ API protection → api-shield/
├─ CAPTCHA alternative → turnstile/
└─ Credential leak detection → waf/ (managed ruleset)

"I need media/content"

Need media?
├─ Image optimization/transformation → images/
├─ Video streaming/encoding → stream/
├─ Browser automation/screenshots → browser-rendering/
└─ Third-party script management → zaraz/

"I need infrastructure-as-code"

Need IaC? → pulumi/ (Pulumi), terraform/ (Terraform), or api/ (REST API)

Product Index

Compute & Runtime

| Product | Reference |

|---------|-----------|

| Workers | references/workers/ |

| Pages | references/pages/ |

| Pages Functions | references/pages-functions/ |

| Durable Objects | references/durable-objects/ |

| Workflows | references/workflows/ |

| Containers | references/containers/ |

| Workers for Platforms | references/workers-for-platforms/ |

| Cron Triggers | references/cron-triggers/ |

| Tail Workers | references/tail-workers/ |

| Snippets | references/snippets/ |

| Smart Placement | references/smart-placement/ |

Storage & Data

| Product | Reference |

|---------|-----------|

| KV | references/kv/ |

| D1 | references/d1/ |

| R2 | references/r2/ |

| Queues | references/queues/ |

| Hyperdrive | references/hyperdrive/ |

| DO Storage | references/do-storage/ |

| Secrets Store | references/secrets-store/ |

| Pipelines | references/pipelines/ |

| R2 Data Catalog | references/r2-data-catalog/ |

| R2 SQL | references/r2-sql/ |

AI & Machine Learning

| Product | Reference |

|---------|-----------|

| Workers AI | references/workers-ai/ |

| Vectorize | references/vectorize/ |

| Agents SDK | references/agents-sdk/ |

| AI Gateway | references/ai-gateway/ |

| AI Search | references/ai-search/ |

Networking & Connectivity

| Product | Reference |

|---------|-----------|

| Tunnel | references/tunnel/ |

| Spectrum | references/spectrum/ |

| TURN | references/turn/ |

| Network Interconnect | references/network-interconnect/ |

| Argo Smart Routing | references/argo-smart-routing/ |

| Workers VPC | references/workers-vpc/ |

Security

| Product | Reference |

|---------|-----------|

| WAF | references/waf/ |

| DDoS Protection | references/ddos/ |

| Bot Management | references/bot-management/ |

| API Shield | references/api-shield/ |

| Turnstile | references/turnstile/ |

Media & Content

| Product | Reference |

|---------|-----------|

| Images | references/images/ |

| Stream | references/stream/ |

| Browser Rendering | references/browser-rendering/ |

| Zaraz | references/zaraz/ |

Real-Time Communication

| Product | Reference |

|---------|-----------|

| RealtimeKit | references/realtimekit/ |

| Realtime SFU | references/realtime-sfu/ |

Developer Tools

| Product | Reference |

|---------|-----------|

| Wrangler | references/wrangler/ |

| Miniflare | references/miniflare/ |

| C3 | references/c3/ |

| Observability | references/observability/ |

| Analytics Engine | references/analytics-engine/ |

| Web Analytics | references/web-analytics/ |

| Sandbox | references/sandbox/ |

| Workerd | references/workerd/ |

| Workers Playground | references/workers-playground/ |

Infrastructure as Code

| Product | Reference |

|---------|-----------|

| Pulumi | references/pulumi/ |

| Terraform | references/terraform/ |

| API | references/api/ |

Other Services

| Product | Reference |

|---------|-----------|

| Email Routing | references/email-routing/ |

| Email Workers | references/email-workers/ |

| Static Assets | references/static-assets/ |

| Bindings | references/bindings/ |

| Cache Reserve | references/cache-reserve/ |

Troubleshooting

Escalated Network Access

Example guidance to the user:

The deploy needs escalated network access to deploy to Cloudflare. I can rerun the command with escalated permissions—want me to proceed?

When to Use

<!-- TODO: review -->

When NOT to Use

<!-- TODO: review -->

想直接用这个技能?

本站把开放许可(MIT / Apache 等)的技能按仓库打包整理到网盘,点一下转存到你自己的网盘,不用一个个从 GitHub 拉。许可未声明的技能只给原始仓库链接,不打包。

它属于哪个仓库

星标★ 503
本站分层T2
该仓技能数31
原文件路径plugins/openai-cloudflare-deploy/skills/openai-cloudflare-deploy/SKILL.md

同一个仓库里的其他技能

看这个仓库的全部 31 个技能