Walrus Tusk
FAQ Agents Open source
Apex predator of the codebase

Walrus
Tusk

AI that writes code with tusks in. Two megafauna incisors, one terminal, zero hesitation.

0.4s
Cold start
1.1M
Token context
-40°C
Rated to
WT Walrus Tusk mascot
Artificial Mind Hive // Cloudflare Ops MCP

AI can plan it.
You approve it.

Walrus Tusk connects Codex, Claude, ChatGPT and other MCP-capable AI agents to Cloudflare operations—with dry runs, explicit approval, deployment checks and an audit trail between intent and production.

Programs

/ what runs on WT
Program 01 · v0.4.2 · live
AMH Cloudflare Ops MCP by WT

An approval-gated Cloudflare operations suite with an optional private Agent Harness: bounded delegation, deterministic verification, OAuth-isolated MCP tools, and verified deploy checks without handing agents raw account credentials.

Open the operator console →

What it does

/ v0.4.2
07 capabilities · approval-gated
01
01
Private Agent Harness

Jack-friendly reusable profiles plus eight automatic process skill folders for safe deploys, live checks, mail loopback, lean handoffs, security review, private MCP access, Google source research, and optional Claude second opinions.

02
02
SafeTry controls

Read-only defaults, explicit approvals, narrow adapters instead of a generic shell, tenant isolation, retention limits, and a tamper-evident audit chain.

03
03
Verified deploy gate

Checks the public target for an explicit 2xx status, rejects redirects, and optionally requires an expected release marker before reporting success.

04
04
Deterministic site health

Zero-AI HTTP checks remain useful for small valid pages and can require an expected text marker to catch a 200 response serving the wrong site.

05
05
Self-catching email loopback

Exercises the configured sending/routing path and records delivery evidence; it does not claim to prove placement in a provider's inbox tab.

06
06
Cloudflare-native connections

Optional OAuth connectors for the official Cloudflare API, Workers Builds, Bindings, Observability, and Docs MCP services, plus Wrangler-based Worker deployment and secrets.

07
07
Guarded operations

Turnstile, DNS, SPF/DMARC/BIMI, Email Routing, Pages cutovers, cache purge, scoped tokens, and account diagnostics stay dry-run or approval-gated where they write.

What it handles

12 operations · dry-run first

Cloudflare Ops MCP is focused on the Cloudflare tasks that regularly break launches, email trust, bot checks, cache freshness, brand display, and AI-agent workflows:

Agents & audit Deploy · record · replay 03
08 Audit logs for applied changes.
11 MCP endpoint deployment on Cloudflare Workers with Wrangler secrets.
12 AI-agent safety defaults: dry-run first, diff display, no token in tool args, no accidental deletes.
Edge & bots Turnstile 01
10 Turnstile widget planning/creation for bot checks.
Email trust SPF · DKIM · DMARC · BIMI · Routing 06
02 SPF detection and planning so you do not accidentally create multiple SPF records.
03 DMARC parsing and policy updates that only change the fields you asked for.
04 BIMI TXT setup with a DMARC enforcement gate.
05 DKIM discovery so the report can tell whether sender keys exist.
06 MX and Cloudflare Email Routing checks.
07 Email Routing destination/rule setup with verified-destination protection.
DNS & records Scan · diff · approve 02
01 DNS record scan, lookup, create, update, no-op detection, and guarded delete.
09 Cloudflare Pages DNS cutovers and cache purge operations.
While it runs Session · orchestrator · continuity
Session · on track Last handoff logged with the release commit, deployment receipt and next safe action.
AI Orchestrator briefed Claude or Codex drives the client; the cheap lane executes under the same dry-run gates.
Continuity keeper Briefing retained on the 4/7/30-day window; stale chatter expires on its own.

Five ways to run it

Version 0.4.2 works five ways
01 CLI run cfops locally with a scoped Cloudflare token.
02 Library import the zero-dependency engine into your own app.
03 Hosted OAuth MCP connect your own Cloudflare account and receive a one-user cfops_ connector key. The owner's API token is never shared.
04 Self-hosted MCP Worker deploy the included Worker with Wrangler for your own team or infrastructure.
05 Private Agent Harness deploy the companion agent/ Worker behind the MCP Worker's AGENT_HARNESS service binding for bounded jobs, health watches, schedules, audit, and the authenticated operator console.
Stage 01 / 05
CLI

run cfops locally with a scoped Cloudflare token.

Safety model

Dry-run by default. Scan before write. Never delete as a side effect. Token hygiene, scoped token only, BIMI precondition, and an audit log for every apply.

01
Run mode
CLI
Library
Hosted OAuth MCP
Self-hosted MCP Worker
Private Agent Harness
Regions
EnglishOpen region → BrasilAbrir região → IndonesiaBuka halaman → 中国打开页面 → PhilippinesBuksan → MéxicoAbrir página → ประเทศไทยเปิดหน้า → Việt NamMở trang → 日本ページを開く → DeutschlandRegion öffnen → FranceOuvrir la région → IndiaOpen region →