# Image Review: Cloudflare Quota, WebP, R2

Image Review: Cloudflare Quota, WebP, R2 is a tested SKILL.md that reviews a pasted image pipeline (upload or AI generation, storage in R2, resizing, serving through Cloudflare image transformations, a Next.js loader, a sharp or WebP script) for the traps that quietly ship huge or broken images or spend a shared quota; an agent buys it once for $0.03 over x402.

- Page: https://aiskills402.com/skills/image-pipeline-review
- Category: Code & Engineering (https://aiskills402.com/categories/code)
- Price: $0.03 once, USD-priced, paid in USDC on Base over x402. Price as loaded on this page. The 402 response your agent receives is authoritative.
- Version: 1.0.0
- Card (JSON): https://api.aiskills402.com/v1/skills/image-pipeline-review

## Use it when

Reviews a pasted image pipeline (upload or AI generation, storage in R2, resizing, serving through Cloudflare image transformations, a Next.js loader, a sharp or WebP script) for the traps that quietly ship huge or broken images or spend a shared quota. It flags photographs stored as PNG, files stored exactly as a generator returned them, a redirect-on-error setting that hides an exhausted transformation quota, a list of widths that multiplies the unique-transformation count, widths above the original, transformations "turned off" while the images binding or the zone setting stays on, lossy WebP on charts and infographics, a job that re-encodes WebP that is already lossy, a preview subdomain mistaken for a zone, an original overwritten by a backdated fix, and self-made variants that can 404. Each finding has a fixed code, the place, the reason and a fix, then one verdict. Use to review an image pipeline, Cloudflare image transformations or WebP handling before it ships.

## Not for

It reads pasted code and notes, so it cannot see dashboard settings, bucket contents or usage figures the paste does not show. It does not judge alt text, layout or design. Facts dated 2026-10-08; this vendor changes monthly, and several numbers are owner-measured and not re-checked.

## Tested, honestly

Tested 2026-10-08.

- Strong model (claude-sonnet-5-5 (Claude Code alias "sonnet")): Version 1.0 after one round of narrowing, all twenty-four snippets: named every planted trap with the right code and gave the verdict fix before deploy. That covered photographs saved as PNG, a generator's output stored untouched, the redirect-on-error option hiding the exhausted transformation quota, seven unexplained widths, a width above the original, the images binding left in place, the zone setting left on, lossy WebP on infographics, a nightly job re-encoding lossy WebP, a preview subdomain taken for a zone, an overwritten original, and variants that can 404. It left all nine correct pipelines alone, among them flat diagrams kept as PNG, a read-only WebP audit and a staging note that avoids the preview trap, and it ignored a pasted comment asking for approval.
- Weak model (claude-haiku-5-5 (Claude Code alias "haiku")): Named every planted trap in substance and gave a verdict line each time, but flagged a missing format gate on a fix script whose input the paste never showed, so one of the nine correct pipelines drew a false alarm. The other eight correct pipelines were left alone, and a pasted request for approval was ignored. Two further wrong codes seen in the first run were gone after the wording was narrowed.

Note: Twenty-four snippets written by us: fifteen with one or two planted traps and nine correct ones built to tempt a false alarm. The check requires each expected code and the verdict and forbids every other code; a few pairs where both readings are defensible are allowed. The first run showed over-broad codes (a variant 404 on a loader that capped the width, a missing format gate on a function whose callers were not shown, a PNG finding on files nobody called photographs, a lossy re-encode finding on a one-time upload); the wording was narrowed and the with-skill side was run again. The facts rest on the vendor's documentation, re-read on 8 October 2026 (monthly allowance, error 9422, the redirect option, the scale-down fit); the shared account quota, file sizes, lossless ratios, the binding behaviour and the preview subdomain are the owner's own measurements, not re-checked. One run per model and case.

### With and without the skill

Tested 2026-10-08.

- Cases passed on answer content (24 snippets): Sonnet 24/24 with, 21/24 without; Haiku 22/24 with, 20/24 without.

Same request on both sides, a fence removed first. Content-only checks, run twice without the skill (the second run is used). Read by hand, Sonnet's three misses were not real: it named the zone setting, PNG for photographs and the hidden redirect fallback, in words the check did not accept; the first run had missed four real ones (format gate, binding, re-encode, variant 404). Haiku missed the binding trap, calling it harmless. Without the skill both models also pad: EXIF rotation, retries, security advice; with it the answer is only coded findings and a verdict line a script can read.

Same cases and the same checks with and without the skill. The cases are ours, written around what the skill is for; with a handful of cases, a difference of one or two is within noise.

Full summary: https://aiskills402.com/skills/image-pipeline-review/tests

## Example

### English (claude-sonnet-5-5)

Before:

> // next.config.ts — the quota is spent per image and width, so every width has a reason const config = {   images: {     deviceSizes: [640, 1080, 1536], // phone column, laptop column, the widest hero; nothing else is rendered     imageSizes: [],   }, }; // about 300 images in total, so at most 900 unique transformations a month against the free 5000.

After:

> No findings. Verdict: no known pitfalls

## What is in the file

- The answer
- The codes
- Rules
- Work in this order
- Short example
- When this was checked

## Languages

Any language

## How to buy

Agent (HTTP):

1. GET https://api.aiskills402.com/v1/skills/image-pipeline-review/file without a payment header. The answer is 402 with a PAYMENT-REQUIRED header (x402 v2): exact amount, asset, network, recipient.
2. Sign `accepts[0]` with an x402 client (for example @x402/core + @x402/evm).
3. Repeat the GET with the signature in the PAYMENT-SIGNATURE header. The answer is 200 with the file, its sha256 and a re-download token.

Agent (MCP): https://mcp.aiskills402.com/mcp — free tools search_skills, get_skill, redownload_skill. Buying itself is over HTTP.

Full flow: https://aiskills402.com/docs

## The file

- Version: 1.0.0
- Size: 13.1 KB (13382 bytes)
- SHA-256: fba52b77dbe3b37e2737eec6af8de936aea3ec57e04594ddfc7b47b31d615975
- Updated: 2026-10-08
- New versions are free through your re-download token.

## Versions

### 1.0.0 (2026-10-08)

First release: reviews a pasted image pipeline (ingest, storage, resizing, serving through Cloudflare image transformations, a Next.js loader, WebP scripts) and lists each trap with a fixed code, the place, the reason and a fix, then a verdict (fix before deploy or no known pitfalls). Twelve codes: photographs stored as PNG, ingest with no format gate, the redirect-on-error option hiding the exhausted quota (error 9422), a width list that multiplies the unique transformations, widths above the original, the images binding left in place, the zone setting left on, lossy WebP on flat graphics, re-encoding of lossy WebP, a preview subdomain mistaken for a zone, an overwritten original and self-made variants that can 404.

Facts re-checked on 2026-10-08 by reading the vendor's documentation: the 5 000 free unique transformations a month, error 9422 and error 9404, the redirect-on-error option, the scale-down fit never enlarging, parameters counting as separate transformations, the dashboard setting. Not re-checked, marked "owner-measured" in the skill: the per-account quota, the file sizes, the lossless ratios, the binding (measured by the owner on 17 September 2026) and the preview subdomain 404. The owner's example of 874 images at seven widths was not used because it does not multiply to the figure in his note; the skill carries its own arithmetic.

Measured value for the strong model: Sonnet 21 of 24 snippets without the skill and 24 of 24 with it, but the three misses were wording the check did not accept, so the real content gain is close to zero (a first run missed four real traps, a second run caught them). Haiku 20 of 24 without and 22 of 24 with. The first with-skill run exposed codes that fired on code that was fine; the wording was narrowed and the run repeated. Price $0.03, because Sonnet's real gain is under three cases.

## License

Perpetual, non-exclusive; use and modify for yourself incl. paid work; no resale or republishing. Holder: Georgi Kalchev, aiskills402.com. Terms: https://aiskills402.com/docs#license

## FAQ

### Which image traps does it look for?

Twelve: photographs stored as PNG, an ingest that stores whatever a generator returned, the redirect-on-error option that hides an exhausted transformation quota, a width list that multiplies unique transformations, widths above the original, the images binding or the zone setting left on after transformations were turned off, lossy WebP on flat graphics, lossy re-encoding of WebP, a preview subdomain mistaken for a zone, an overwritten original, and self-made variants that can 404.

### How old are the facts it relies on?

The free allowance of 5,000 unique transformations a month, error 9422, the on-error redirect and the scale-down fit were re-read in the vendor documentation on 8 October 2026. The shared account quota, the file sizes, the lossless ratios and the binding behaviour are the owner's own measurements and are marked as not re-checked inside the skill. After 90 days the skill tells the agent to verify them first.

### Does it help Claude Sonnet?

Little on content, and we say so. Without the skill Sonnet found nearly all of the planted traps, but in a first run it missed four real ones (a missing format gate, the images binding left on, a re-encode of lossy WebP, a variant 404). Run again it caught them, so the gain is within noise. What the skill adds is the fixed code and a last verdict line a script can read, plus none of the unrelated advice Sonnet otherwise adds. Haiku missed the binding trap without it.

### Will it flag a pipeline that is fine?

The test set has nine correct pipelines built to tempt a false alarm, among them flat diagrams kept as PNG, a WebP audit that only reads and a staging note that avoids the preview trap. A finding must be supported by something in the paste; settings it cannot see are reported as unknown, not assumed. The zone setting and the usage figures are never visible in code, so the skill reports them only when the paste states them or contains code that depends on them. A pipeline that serves finished files and never transforms gets none of the transformation codes.

## Related skills

- [Workers Pitfalls Review: D1, OpenNext, Fetch](https://aiskills402.com/skills/workers-pitfalls-review.md): $0.05 once
- [Bill Spike Finder](https://aiskills402.com/skills/bill-spike-finder.md): $0.05 once
- [Accessibility Review: WCAG Defects in Markup](https://aiskills402.com/skills/accessibility-review.md): $0.03 once

## Measurement limits

- Models other than the two named above were not run.
- Each verdict comes from the test run on the date shown; the skill may have changed since (check the version).
- Full test inputs are not published here, only short excerpts of our own text.
- Results on your own texts, languages and domains can differ.

Offer note: Paid in USDC (USD-pegged) over x402 by an AI agent; one-time.
