Skip to content
← writing

Block scanners at the edge with one Cloudflare rule

cloudflare
security
waf
infrastructure

Ask your agent to implement this

Read the full writeup at https://seangeng.com/writing/block-scanners-at-the-edge.md and implement it in my project.

It covers: Block scanners at the edge with one Cloudflare rule. Bots hammer every site for /.env, /.git, /wp-login and a hundred other 'leaky paths'. Here's a single Cloudflare WAF custom rule that blocks them before they ever reach your origin, plus a generator and a Claude Code skill to apply it.

Requirements:
- Follow the technique/approach exactly as described in the writeup.
- Adapt names, colors, and styling to my project's existing conventions.
- If it's a component, make it reusable with sensible props and TypeScript types.
- Keep it accessible: semantic HTML, keyboard support, and respect prefers-reduced-motion.
- When done, tell me which files you created or changed and how to use it.

Paste into Claude Code, Codex, Cursor, or any agent. view raw .md