# Cloudflare One

> Cloudflare One is an officially published skill from Cloudflare. Anomity scores its risk at 20 out of 100 (low).

- **Canonical URL:** https://catalog.anomity.ai/skill/cloudflare-one
- **Kind:** Skill
- **Publisher:** Cloudflare
- **Trust level:** official
- **Risk score:** 20/100 (low)
- **Website:** https://developers.cloudflare.com/cloudflare-one/
- **Last updated:** 2026-09-02
- **JSON:** https://catalog.anomity.ai/api/entries/skill/cloudflare-one

## Description

Cloudflare's skill for configuring Zero Trust and SASE across its product line — access policies, tunnels, gateway rules, and the identity integration that ties them together.

It declares outbound network and credential access. What makes this one notable is the subject matter: the skill configures the controls that decide who can reach what. A mistake here does not break a build, it opens a path. Agent-generated access policy deserves the same review as agent-generated firewall rules — read the diff, and prefer applying through a change process rather than directly.

## Why it scored 20

The score starts at the catalog's neutral base of 50 and moves only through the signals below. The formula is published at https://catalog.anomity.ai/about — there is no model and no hidden heuristic.

| Signal | Contribution | Severity | Evidence |
| --- | --- | --- | --- |
| Published by the vendor | -40 | trust offset |  |
| 1 high-risk capability: credentials:access | +10 | high |  |

Clamped result: **20/100**, band **low**.

## Capabilities

| Capability | Name | Security implication |
| --- | --- | --- |
| `network:outbound` | Outbound network | Can make outbound network requests. Required for hosted model providers and remote APIs; also the path for data exfiltration if combined with read access. |
| `credentials:access` | Credentials access | Reads provider API keys, OAuth tokens, or other secrets from the host keychain or environment. |

## Related skills

- [Azure Deploy](https://catalog.anomity.ai/skill/azure-deploy) — risk 45 (medium)
- [Azure Diagnostics](https://catalog.anomity.ai/skill/azure-diagnostics) — risk 45 (medium)
- [Azure Compliance](https://catalog.anomity.ai/skill/azure-compliance) — risk 20 (low)
- [Azure Cost](https://catalog.anomity.ai/skill/azure-cost) — risk 20 (low)
- [Convex Advisor](https://catalog.anomity.ai/skill/convex-advisor) — risk 20 (low)
- [ElevenLabs Agents](https://catalog.anomity.ai/skill/elevenlabs-agents) — risk 20 (low)

---

Source: Anomity Catalog (https://catalog.anomity.ai/). Scoring methodology: https://catalog.anomity.ai/about. Machine-readable index: https://catalog.anomity.ai/llms.txt · https://catalog.anomity.ai/openapi.json
