Skip to content
Machine Learning
Skill

/cloudflare

Query Cloudflare HTTP analytics AND manage security rules across zones. Traffic investigation (top IPs, paths, user agents, bot scores, timelines, scrape analysis) plus export and port of Custom Rules + Rate Limit Rules between zones (e.g. civitai.com -> civitai.red).

BOOST
From plugin
civitai
7.3k48 skills15 agents3 commands
Install
$ npx -y skills add civitai/civitai --skill cloudflare --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/cloudflare

Context preview

The summary Claude sees to decide when to auto-load this skill.

Query Cloudflare HTTP analytics AND manage security rules across zones. Traffic investigation (top IPs, paths, user agents, bot scores, timelines, scrape analysis) plus export and port of Custom Rules + Rate Limit Rules between zones (e.g. civitai.com -> civitai.red).

SKILL.md

cloudflare.SKILL.md
name: cloudflare
description: Query Cloudflare HTTP analytics AND manage security rules across zones. Traffic investigation (top IPs, paths, user agents, bot scores, timelines, scrape analysis) plus export and port of Custom Rules + Rate Limit Rules between zones (e.g. civitai.com -> civitai.red).

Cloudflare Analytics + Rule Management

Query Cloudflare HTTP traffic analytics and manage security rules (Custom Rules, Rate Limit Rules) across zones. The `CF_API_TOKEN` in `.env` needs **Zone Analytics: Read** for analytics, and **Zone WAF: Edit** for rule management.

Running Commands

node .claude/skills/cloudflare/query.mjs <command> [options]

Commands

| Command | Description | |---------|-------------| | `top-clients` | Top IPs by request count | | `top-paths` | Top request paths | | `top-agents` | Top user agents | | `timeline` | Requests per minute timeline (bar chart) | | `ip <addr>` | Full breakdown for a specific IP (paths, UAs, statuses, geo) | | `scrape` | Full scrape analysis — top IPs, paths, UAs + detail on high-volume IPs | | `bot-scores` | Bot score distribution | | `bot-clients` | Top clients with low bot scores (likely bots) | | `firewall` | Recent firewall/WAF events | | `rate-limits` | Current rate limit rules | | `waf-rules` | Current WAF custom rules | | `list-zones` | List all accessible zones (id, name, plan) | | `export-rules <zone>` | Dump Custom Rules + Rate Limit Rules from a zone | | `port-rules` | Copy rules between zones (dry-run by default) |

Flags

| Flag | Description | |------|-------------| | `--start`, `--from` | Start time: relative (`-1h`, `-2d`, `-30m`), time (`16:41`), or ISO datetime | | `--end`, `--to` | End time (default: now) | | `--limit` | Max results (default: 20) | | `--path` | Filter by path pattern using SQL LIKE (`/api/%`, `/api/trpc/%`) | | `--ip` | Filter by client IP | | `--score` | Max bot score for `bot-clients` (default: 10) | | `--source`, `--target` | Zone name or id (used by `port-rules`) | | `--phase` | `custom`, `ratelimit`, or `all` (default) for rule commands | | `--out` | Write `export-rules` output to a JSON file | | `--skip-disabled` | When porting, skip rules with `enabled: false` | | `--skip-hosts` | Comma-separated list of hosts; rules referencing them are skipped | | `--rewrite-host FROM:TO` | Replace `"FROM"` with `"TO"` in rule expressions during port | | `--only` | Comma-separated substrings; only port rules whose description matches | | `--pro-compat` | Strip Enterprise-only syntax to fit Pro/Free target zones (see below) | | `--apply` | Actually write. Without this, `port-rules` is a dry run |

Only `--skip-disabled`, `--pro-compat` and `--apply` carry no value; each also accepts an explicit `--apply true` / `--apply false`. Every other flag must be given one — a bare flag, or one whose value starts with `--`, is an error rather than the string `'true'` it used to become. Use `--flag=value` for a value that legitimately starts with `--`.

Examples

# Full scrape analysis for a time window
node .claude/skills/cloudflare/query.mjs scrape --start "2026-03-24 16:41" --end "2026-03-24 19:08"

# Top IPs hitting API endpoints in the last 2 hours
node .claude/skills/cloudflare/query.mjs top-clients --start -2h --path "/api/%"

# What paths is a specific IP hitting?
node .claude/skills/cloudflare/query.mjs ip 1.2.3.4 --start -6h

# Traffic timeline for API/trpc routes
node .claude/skills/cloudflare/query.mjs timeline --start -1h --path "/api/trpc/%"

# Find likely bots (low bot score) hitting API
node .claude/skills/cloudflare/query.mjs bot-clients --start -3h --score 5 --path "/api/%"

# Top user agents on search-related paths
node .claude/skills/cloudflare/query.mjs top-agents --start -2h --path "/api/trpc/image%"

# Check current rate limit rules
node .claude/skills/cloudflare/query.mjs rate-limits

# List all zones (id, name, plan)
node .claude/skills/cloudflare/query.mjs list-zones

# Export civitai.com rules (custom + rate limit) to a file
node .claude/skills/cloudflare/query.mjs export-rules civitai.com --out com-rules.json

# Dry-run a port from civitai.com to civitai.red — preview only
node .claude/skills/cloudflare/query.mjs port-rules \
  --source civitai.com --target civitai.red \
  --skip-disabled \
  --skip-hosts api.civitai.com,metrics.civitai.com,education.civitai.com,image.civitai.com,meilisearch-v1-9.civitai.com,meilisearch-v1-6.civitai.com,meilisearch-metrics.civitai.com \
  --rewrite-host civitai.com:civitai.red \
  --pro-compat

# Same thing, but actually write it (REPLACES target rulesets wholesale)
node .claude/skills/cloudflare/query.mjs port-rules \
  --source civitai.com --target civitai.red \
  --skip-disabled \
  --skip-hosts api.civitai.com,metrics.civitai.com,education.civitai.com,image.civitai.com,meilisearch-v1-9.civitai.com,meilisearch-v1-6.civitai.com,meilisearch-metrics.civitai.com \
  --rewrite-host civitai.com:civitai.red \
  --pro-compat \
  --apply

# Port only specific rules (match by description substring)
node .claude/skills/cloudflare/query.mjs port-rules \
  --source civitai.com --target civitai.red --phase ratelimit \
  --only "Global Limit,Rate limit trpc (No Regex)" \
  --rewrite-host civitai.com:civitai.red \
  --pro-compat --apply

Porting Security Rules Between Zones

`port-rules` replaces the target zone's Custom Rules ruleset and/or Rate Limit Rules entrypoint with a filtered + transformed copy of the source zone's rules. It **overwrites** the target ruleset — existing rules on the target are wiped.

What gets ported

The Cloudflare "Security Rules" surface maps to two phase entrypoints:

| Phase | UI name | Flag value | |-------|---------|-----------| | `http_request_firewall_custom` | Custom Rules | `--phase custom` | | `http_ratelimit` | Rate Limit Rules | `--phase ratelimit` |

Managed Rules, IP Access Rules, Zone Lockdown, and User Agent Blocking are **not** ported.

Filters

Without filters, every rule fr

Read more
Ships withcivitai

A repository of models, textual inversions, and more

Get the whole plugin

Other skills on civitai.