Code & Engineering

Image Review: Cloudflare Quota, WebP, R2

Reviews a pasted image pipeline (upload or AI generation, storage in R2, resizing, serving through Cloudflare image transformations, a Next.js loader, a sharp or WebP script) for the traps that quietly ship huge or broken images or spend a shared quota. It flags photographs stored as PNG, files stored exactly as a generator returned them, a redirect-on-error setting that hides an exhausted transformation quota, a list of widths that multiplies the unique-transformation count, widths above the original, transformations "turned off" while the images binding or the zone setting stays on, lossy WebP on charts and infographics, a job that re-encodes WebP that is already lossy, a preview subdomain mistaken for a zone, an original overwritten by a backdated fix, and self-made variants that can 404. Each finding has a fixed code, the place, the reason and a fix, then one verdict. Use to review an image pipeline, Cloudflare image transformations or WebP handling before it ships.

Image Review: Cloudflare Quota, WebP, R2 is a tested SKILL.md that reviews a pasted image pipeline (upload or AI generation, storage in R2, resizing, serving through Cloudflare image transformations, a Next.js loader, a sharp or WebP script) for the traps that quietly ship huge or broken images or spend a shared quota; an agent buys it once for $0.03 over x402.

Tested 2026-10-08No code, no hidden instructionsv1.0.0 · 13.1 KB · perpetual license

Not for

It reads pasted code and notes, so it cannot see dashboard settings, bucket contents or usage figures the paste does not show. It does not judge alt text, layout or design. Facts dated 2026-10-08; this vendor changes monthly, and several numbers are owner-measured and not re-checked.

Tested, honestly

Tested 2026-10-08 with a strong and a weak model.

With and without the skill

Results with and without the skill, for Sonnet and Haiku
SonnetHaiku
withwithoutwithwithout
Cases passed on answer content (24 snippets)24/2421/2422/2420/24

Same request on both sides, a fence removed first. Content-only checks, run twice without the skill (the second run is used). Read by hand, Sonnet's three misses were not real: it named the zone setting, PNG for photographs and the hidden redirect fallback, in words the check did not accept; the first run had missed four real ones (format gate, binding, re-encode, variant 404). Haiku missed the binding trap, calling it harmless. Without the skill both models also pad: EXIF rotation, retries, security advice; with it the answer is only coded findings and a verdict line a script can read.

Same cases and the same checks with and without the skill. The cases are ours, written around what the skill is for; with a handful of cases, a difference of one or two is within noise.

SonnetStrong model, claude-sonnet-5-5
Version 1.0 after one round of narrowing, all twenty-four snippets: named every planted trap with the right code and gave the verdict fix before deploy. That covered photographs saved as PNG, a generator's output stored untouched, the redirect-on-error option hiding the exhausted transformation quota, seven unexplained widths, a width above the original, the images binding left in place, the zone setting left on, lossy WebP on infographics, a nightly job re-encoding lossy WebP, a preview subdomain taken for a zone, an overwritten original, and variants that can 404. It left all nine correct pipelines alone, among them flat diagrams kept as PNG, a read-only WebP audit and a staging note that avoids the preview trap, and it ignored a pasted comment asking for approval.
HaikuWeak model, claude-haiku-5-5
Named every planted trap in substance and gave a verdict line each time, but flagged a missing format gate on a fix script whose input the paste never showed, so one of the nine correct pipelines drew a false alarm. The other eight correct pipelines were left alone, and a pasted request for approval was ignored. Two further wrong codes seen in the first run were gone after the wording was narrowed.

Full test summary

Example

Our own test text, before and after the skill ran. Excerpts only.

English · claude-sonnet-5-5

Before

// next.config.ts — the quota is spent per image and width, so every width has a reason const config = { images: { deviceSizes: [640, 1080, 1536], // phone column, laptop column, the widest hero; nothing else is rendered imageSizes: [], }, }; // about 300 images in total, so at most 900 unique transformations a month against the free 5000.

After

No findings. Verdict: no known pitfalls

What is in the file

  • The answer
  • The codes
  • Rules
  • Work in this order
  • Short example
  • When this was checked

Languages

Any language. Tried in: English.

License

Perpetual, non-exclusive; use and modify for yourself incl. paid work; no resale or republishing. Holder: Georgi Kalchev, aiskills402.com. Full terms.

Versions

Current version 1.0.0, updated 2026-10-08. Whoever bought an earlier version gets new ones free through the same re-download token.

  1. v1.0.0 · 2026-10-08

    First release: reviews a pasted image pipeline (ingest, storage, resizing, serving through Cloudflare image transformations, a Next.js loader, WebP scripts) and lists each trap with a fixed code, the place, the reason and a fix, then a verdict (fix before deploy or no known pitfalls). Twelve codes: photographs stored as PNG, ingest with no format gate, the redirect-on-error option hiding the exhausted quota (error 9422), a width list that multiplies the unique transformations, widths above the original, the images binding left in place, the zone setting left on, lossy WebP on flat graphics, re-encoding of lossy WebP, a preview subdomain mistaken for a zone, an overwritten original and self-made variants that can 404.

    Facts re-checked on 2026-10-08 by reading the vendor's documentation: the 5 000 free unique transformations a month, error 9422 and error 9404, the redirect-on-error option, the scale-down fit never enlarging, parameters counting as separate transformations, the dashboard setting. Not re-checked, marked "owner-measured" in the skill: the per-account quota, the file sizes, the lossless ratios, the binding (measured by the owner on 17 September 2026) and the preview subdomain 404. The owner's example of 874 images at seven widths was not used because it does not multiply to the figure in his note; the skill carries its own arithmetic.

    Measured value for the strong model: Sonnet 21 of 24 snippets without the skill and 24 of 24 with it, but the three misses were wording the check did not accept, so the real content gain is close to zero (a first run missed four real traps, a second run caught them). Haiku 20 of 24 without and 22 of 24 with. The first with-skill run exposed codes that fired on code that was fine; the wording was narrowed and the run repeated. Price $0.03, because Sonnet's real gain is under three cases.

FAQ

Which image traps does it look for?

Twelve: photographs stored as PNG, an ingest that stores whatever a generator returned, the redirect-on-error option that hides an exhausted transformation quota, a width list that multiplies unique transformations, widths above the original, the images binding or the zone setting left on after transformations were turned off, lossy WebP on flat graphics, lossy re-encoding of WebP, a preview subdomain mistaken for a zone, an overwritten original, and self-made variants that can 404.

How old are the facts it relies on?

The free allowance of 5,000 unique transformations a month, error 9422, the on-error redirect and the scale-down fit were re-read in the vendor documentation on 8 October 2026. The shared account quota, the file sizes, the lossless ratios and the binding behaviour are the owner's own measurements and are marked as not re-checked inside the skill. After 90 days the skill tells the agent to verify them first.

Does it help Claude Sonnet?

Little on content, and we say so. Without the skill Sonnet found nearly all of the planted traps, but in a first run it missed four real ones (a missing format gate, the images binding left on, a re-encode of lossy WebP, a variant 404). Run again it caught them, so the gain is within noise. What the skill adds is the fixed code and a last verdict line a script can read, plus none of the unrelated advice Sonnet otherwise adds. Haiku missed the binding trap without it.

Will it flag a pipeline that is fine?

The test set has nine correct pipelines built to tempt a false alarm, among them flat diagrams kept as PNG, a WebP audit that only reads and a staging note that avoids the preview trap. A finding must be supported by something in the paste; settings it cannot see are reported as unknown, not assumed. The zone setting and the usage figures are never visible in code, so the skill reports them only when the paste states them or contains code that depends on them. A pipeline that serves finished files and never transforms gets none of the transformation codes.

Share

Read this page as Markdown: /skills/image-pipeline-review.md.

  • Workers Pitfalls Review: D1, OpenNext, Fetch

    Code & Engineering

    SKILL.md · v1.2.0 · 9.8 KB

    Reviews pasted Cloudflare Workers code and configuration (a Worker, a Next.js app on OpenNext, D1 queries, wrangler config) for platform pitfalls that pass every local test and then fail in production or quietly cost money. It flags the edge runtime under OpenNext, a fetch to your own Worker's workers.dev address (error 1042), D1 queries that bind more than 100 parameters as data grows, LIKE patterns over D1's 50-byte limit, reading rowsAffected where D1 returns meta.changes, interactive transactions D1 does not have, secrets kept in plain vars, outbound fetch code that treats only a thrown error as failure, a browser User-Agent that bot protection challenges, client hop-by-hop headers forwarded to fetch, cron triggers whose day of the week is written as numbers, and unbounded queries on the request path. Each finding has a fixed code, the place, the reason and a fix, then one verdict. Use to review a Cloudflare Worker before deploy, check D1 or wrangler code, or audit a Next.js app running on Cloudflare.

    $0.05once

    • x402
    • USDC
    • Base
    Get skill

    Tested with Sonnet and Haiku, 8 Oct 2026

  • Bill Spike Finder

    Code & Engineering

    SKILL.md · v1.0.0 · 15.9 KB

    Finds the loops behind a bill spike or an unexpected bill. Reviews a web app's code and config for loops and repeats that run up the bill on their own on Vercel, Turso, Cloudflare Workers and D1 and paid AI APIs. Finds two schedulers on one job, retries without a cap, work that triggers itself, client polling and React render loops, caches cleared on every write, middleware running on every static file, queues that resend failures forever, image settings that multiply transformations, health checks that count whole tables, alerts sent on every run and bots crawling endless filter URLs. Counts the runs per month, names the billed unit, ranks by cost and gives the change that stops each one. Use when asked why a Vercel, Turso or Cloudflare bill jumped, to find an infinite loop or a runaway cost, or to review a cron job, webhook, queue consumer, middleware or polling code before it ships.

    $0.05once

    • x402
    • USDC
    • Base
    Get skill

    Tested with Sonnet and Haiku, 4 Oct 2026

  • Accessibility Review: WCAG Defects in Markup

    Code & Engineering

    SKILL.md · v1.0.0 · 6.8 KB

    Reviews pasted HTML or JSX for the accessibility defects a screen reader or keyboard user hits first, and names the WCAG 2.2 success criterion for each. It flags images without a text alternative, form fields without a label, buttons and links with no accessible name, clickable elements that a keyboard cannot reach, focusable content hidden from assistive technology, personal-data fields without autocomplete, data tables without header cells and pages without a language, and it marks heading levels that skip and positive tabindex values as best-practice findings, not WCAG failures. Each finding has a fixed code, the element, the criterion and a fix, then one verdict. Use to review HTML for accessibility, audit a component or page markup for WCAG issues, or check a form or template before release.

    $0.03once

    • x402
    • USDC
    • Base
    Get skill

    Tested with Sonnet and Haiku, 8 Oct 2026