v1.0.0 · 2026-10-08
First release: reviews pasted Next.js App Router code and config that runs on Cloudflare through OpenNext for caching and ISR mistakes, with a fixed code, the place, the reason and a fix per finding, then a verdict (will break, fix before deploy, no known pitfalls). Will break: a cached function whose shape changed under the same key, a static page reading D1 during the build, a redirect added over a path cached as 404, a middleware matcher that skips robots.txt and sitemap files. Fix before deploy: a dynamic route without generateStaticParams, force-dynamic losing the back-forward cache, a wildcard no-cache header, a writer evicting a tag on every event, s-maxage trusted to cap database reads, whole pages cached instead of the data, a clock stored inside cached data.
How the facts were checked (the writer, 2026-10-08, read-only): - Next.js reference page for the cached function: read; it confirms the cache persists across requests and deployments, that the key parts and arguments form the key, that tags do not identify the function, and that the API is replaced by a cache directive in Next.js 16 (so the skill never reports the old API itself). - Next.js reference page for the static params function: read; it confirms an empty array is how paths are rendered on first visit and how ISR is enabled at runtime, and that revalidation does not call it again. - OpenNext Cloudflare caching page: read; it confirms R2 for the incremental cache, D1 or Durable Objects for the tag cache, and that on-demand revalidation goes through the tag cache. - Not re-checked by the writer, marked as such in the skill: the rendering result for a dynamic route without the params function (owner-measured 2026-10-08, Next.js 16.3 and OpenNext 1.20), the cached-404 plus redirect behaviour and the matcher behaviour (owner-measured, September 2026), the wildcard header effect (owner note). - Left out on purpose because the owner's own re-measurement on 2026-10-08 shows they no longer hold: headers() in generateMetadata giving 500, and a dynamic Open Graph image reading D1 failing. Both are controls in the test set.
Measured 2026-10-08 (one run per model and snippet, read by hand after the run): Sonnet 23 of 23 with the skill, 21 of 23 without; Haiku 23 of 23 with (one finding lacked its code tag), 20 of 23 without. Sonnet gain is 2, so the price stays $0.03.
Test-set change after the run (checks, not the skill): on a sound snippet a bare "No findings." is now accepted without the second verdict line, because the request said to answer exactly that (Haiku did so twice); a fault verdict next to it still fails. Control updated to match. The bare-side misses on the redirect, params and two-fault snippets were real, so no other check was widened.
FAQ: dropped the question about other hosts to make room for "Does it help Claude Sonnet?"; the Cloudflare-only scope stays in the skill text.