plugins/cloudflare/skills/dns/SKILL.md
Use this skill when the user asks about Cloudflare DNS, managing DNS records, domain zones, DNSSEC, proxied records, or managing DNS with Pulumi.
npx skillsauth add nsheaps/ai-mktpl cloudflare-dnsInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
Cloudflare DNS is one of the fastest authoritative DNS providers. It supports proxy mode (orange cloud), DNSSEC, wildcard records, and API-based management.
cloudflare.Zone, cloudflare.Record| Type | Use Case | Example |
| ----- | ----------------------- | --------------------------------- |
| A | IPv4 address | example.com -> 1.2.3.4 |
| AAAA | IPv6 address | example.com -> 2001:db8::1 |
| CNAME | Alias | www -> example.com |
| MX | Mail server | example.com -> mail.example.com |
| TXT | Verification, SPF, DKIM | v=spf1 include:... |
| SRV | Service discovery | _sip._tcp.example.com |
When proxied: true, Cloudflare's CDN, WAF, and DDoS protection apply to the record. When proxied: false (grey cloud), it's DNS-only.
import * as cloudflare from "@pulumi/cloudflare";
// Zone
const zone = new cloudflare.Zone("example", {
accountId,
zone: "example.com",
});
// A Record
const www = new cloudflare.Record("www", {
zoneId: zone.id,
name: "www",
type: "A",
content: "1.2.3.4",
proxied: true,
});
// CNAME Record
const api = new cloudflare.Record("api", {
zoneId: zone.id,
name: "api",
type: "CNAME",
content: "api-server.example.com",
proxied: true,
});
// MX Record
const mx = new cloudflare.Record("mx", {
zoneId: zone.id,
name: "@",
type: "MX",
content: "mail.example.com",
priority: 10,
});
tools
Manually reproduce what the github-app plugin's SessionStart hook does to make a GitHub App installation token usable in the current session — materialize the PEM, generate the token, isolate GH_CONFIG_DIR, write the runtime env file, and wire CLAUDE_ENV_FILE so every Bash call sees GH_TOKEN/GITHUB_TOKEN. Use when the hook did not run, the token is missing from the environment, or a shell/teammate needs the token wired up by hand. <example>GH_TOKEN isn't set even though github-app is configured</example> <example>the github-app SessionStart hook didn't run, set up the token manually</example> <example>wire the github app token into CLAUDE_ENV_FILE</example> <example>gh keeps falling back to the wrong account, isolate GH_CONFIG_DIR</example>
tools
Manually configure the GitHub App bot git identity the way the github-app plugin's SessionStart hook does — resolve the app slug and bot user ID, build the <slug>[bot] name and noreply email, set GIT_AUTHOR_*/GIT_COMMITTER_* env vars, and write an isolated GIT_CONFIG_GLOBAL with the gh auth git-credential helper. Use when commits are attributed to the wrong account, "Author identity unknown" appears, or git identity must be set up by hand. <example>my commits are showing up as the handler, not the bot</example> <example>git says Author identity unknown after the github-app hook ran</example> <example>configure the github app bot git identity manually</example> <example>set up the gh credential helper for git push</example>
tools
Manages spec files for requirements capture and validation
tools
# Bash Chaining Alternatives This skill teaches you how to work around the bash command chaining restriction enforced by this plugin. ## Why Chaining is Blocked The `bash-command-rejection` plugin blocks these operators: | Operator | Name | Why Blocked | | -------- | ---------- | ----------------------------------------------------------------------------------- | | `&&` | AND chain | Runs cmd2 only if cmd1 su