SKILL.md
Cloudflare Management via MCP
Use this skill when you need to manage Cloudflare zones, DNS records, Workers, KV storage, R2 buckets, or cache purging.
Available Tools
| Tool | What it does |
|---|---|
cf_zones |
List Cloudflare zones (domains) |
cfdnslist |
List DNS records for a zone |
cfdnscreate |
Create a DNS record |
cfdnsdelete |
Delete a DNS record |
cfworkerslist |
List Workers scripts |
cfworkerdelete |
Delete a Workers script |
cfkvnamespaces |
List KV namespaces |
cfkvkeys |
List keys in a KV namespace |
cfkvget |
Get a value from KV |
cfkvput |
Write a value to KV |
cfkvdelete |
Delete a KV key |
cfr2buckets |
List R2 storage buckets |
cfcachepurge |
Purge cache (all or specific URLs) |
Workflow
- Start with
cf_zonesto discover available zones and get zone IDs - Use zone IDs for DNS operations (
cfdnslist,cfdnscreate,cfdnsdelete) - Workers, KV, and R2 use the account ID (configured via
CLOUDFLAREACCOUNTID) - Cache purge requires a zone ID and optionally specific URLs
Key Patterns
- DNS record creation requires
zone_id,type(A, CNAME, MX, TXT),name, andcontent - KV operations need a
namespaceid; get it fromcfkv_namespacesfirst - Cache purge with no URLs purges everything for the zone; confirm with the user before doing this
- All tools require
CLOUDFLAREAPITOKENandCLOUDFLAREACCOUNTIDenv vars
Error Scenarios
- 403 or authentication errors: token missing, wrong permissions, or account id not set for Workers/KV/R2
- Zone or record not found: run
cfzonesandcfdns_listto confirm ids before create/delete - KV namespace errors: pick
namespaceidfromcfkv_namespacesbefore get/put/delete - Cache purge failures: confirm zone id and URL list format; full-zone purge needs explicit user approval
Safety
- Always confirm before deleting DNS records, Workers, or KV keys
- Always confirm before purging all cache (use specific URLs when possible)
- DNS propagation takes time; warn users that changes may not be instant