Cloudflare’s vulnerability work is a process story more than a model story. Their open-sourced security-audit skill is the single-repo starting point, and the fleet harness it seeded is what happens when you run that process across a lot of code for a long time.
Agents hunt and produce candidates in volume, then other agents try to knock those candidates down. What survives has to carry a source-grounded claim, not a confident vibe from the hunter who found it.
The fleet numbers make the filter visible. Tens of thousands of raw leads compress into a smaller set that still stands after validation, dedup, and judgment. One pass is not enough either, because repeated runs cover ground a single audit misses.
When finding bugs gets cheap, the scarce work is the pipeline that decides which ones are real. That pipeline is the part worth copying.