Reviews pasted Cloudflare Workers code and configuration (a Worker, a Next.js app on OpenNext, D1 queries, wrangler config) for platform pitfalls that pass every local test and then fail in production or quietly cost money. It flags the edge runtime under OpenNext, D1 queries that bind more than 100 parameters as data grows, LIKE patterns over D1's 50-byte limit, reading rowsAffected where D1 returns meta.changes, interactive transactions D1 does not have, secrets kept in plain vars, outbound fetch code that treats only a thrown error as failure, client hop-by-hop headers forwarded to fetch, and unbounded queries on the request path. Each finding has a fixed code, the place, the reason and a fix, then one verdict. Use to review a Cloudflare Worker before deploy, check D1 or wrangler code, or audit a Next.js app running on Cloudflare.
Workers Pitfalls Review: D1, OpenNext, Fetch is a tested SKILL.md that reviews pasted Cloudflare Workers code and configuration (a Worker, a Next.js app on OpenNext, D1 queries, wrangler config) for platform pitfalls that pass every local test and then fail in production or quietly cost money; an agent buys it once for $0.03 over x402.
Not for
General code review, style, performance tuning or security beyond the listed pitfalls, and anything that needs the running system: it reads pasted code, so it cannot see indexes, data sizes or bindings that the paste does not show, and it does not cover Durable Objects, Queues or KV.
Tested, honestly
Tested 2026-10-08 with a strong and a weak model.
With and without the skill
Results with and without the skill, for Sonnet and Haiku |
| with | without | with | without |
|---|
| Planted pitfalls named (12 snippets) |
| Planted pitfalls named (12 snippets) | 12/12 | 12/12 | 12/12 | 9/12 |
|---|
One run per model and snippet, the same word-based check on both sides. Sonnet found all twelve planted pitfalls without the skill too, so for Sonnet the skill adds no detection, only the fixed codes and verdict a program can read. Haiku without the skill called the edge runtime under OpenNext fine, twice, and did not mention D1's 50-byte LIKE limit; with the skill it named all twelve. On correct code the side without the skill gave general advice, such as validating a transfer amount, which this test neither rewards nor penalises.
Same cases and the same checks with and without the skill. The cases are ours, written around what the skill is for; with a handful of cases, a difference of one or two is within noise.
- SonnetStrong model, claude-sonnet-5-5
- Named every planted pitfall with the right code and verdict: the edge runtime under OpenNext, BEGIN and COMMIT against D1, an inArray over saved ids and a bulk insert of uploaded rows past 100 parameters, a LIKE pattern built from the search box, rowsAffected read from a D1 result, an uptime probe that only treats a thrown error as down, client headers forwarded to fetch, a live key in vars and a GROUP BY over a growing table on every page view, and it ignored a comment telling the reviewer to answer No findings. It left six correct snippets alone, including a fixed three-item inArray, public vars and a batch() transfer. It failed one case by our strict check: on the header-forwarding proxy it also flagged the fetch status, which a proxy correctly passes through.
- HaikuWeak model, claude-haiku-5-5
- Found every planted pitfall as well, but raised two false alarms: the same fetch-status flag on the proxy, and a secret-in-vars finding on vars that held only a public site address and a locale.
Full test summary
Example
Our own test text, before and after the skill ran. Excerpts only.
English · claude-sonnet-5-5
Before
// src/index.ts — a plain Worker, deployed with wrangler deploy
export default {
async fetch(): Promise<Response> {
return new Response("hello");
},
};
After
No findings.
Verdict: no known pitfalls
What is in the file
- The answer
- The codes
- Rules
- Work in this order
- Short example
Languages
Any language. Tried in: English.
License
Perpetual, non-exclusive; use and modify for yourself incl. paid work; no resale or republishing. Holder: Georgi Kalchev, aiskills402.com. Full terms.
Versions
Current version 1.0.0, updated 2026-10-08. Whoever bought an earlier version gets new ones free through the same re-download token.
v1.0.0 · 2026-10-08
First release: reviews pasted Cloudflare Workers code and configuration for platform pitfalls and lists each with a fixed code, the place, the reason and a fix, then a verdict (will break, fix before deploy, no known pitfalls). Breaks at once: the edge runtime under OpenNext, interactive D1 transactions. Breaks later or costs money: more than 100 bound D1 parameters, LIKE patterns over 50 bytes, rowsAffected instead of meta.changes, fetch code that only catches thrown errors, forwarded hop-by-hop headers, secrets in vars, unbounded queries on the request path.
FAQ
Which pitfalls does it look for?
Nine: the edge runtime under OpenNext, interactive D1 transactions, D1 queries past 100 bound parameters, LIKE patterns over 50 bytes, rowsAffected where D1 returns meta.changes, fetch code that only catches thrown errors, client hop-by-hop headers forwarded to fetch, secrets in plain vars and unbounded queries on the request path. Each was checked against Cloudflare's or OpenNext's documentation or measured in our own production.
Does it help Claude Sonnet?
Not with finding them: in our test Sonnet named all twelve planted pitfalls without the skill as well. What the skill adds there is a fixed list of codes and a verdict line that a pipeline can act on. Claude Haiku is different: without the skill it called the edge runtime under OpenNext fine and missed the LIKE limit, and with it Haiku found all twelve.
Will it flag code that is fine?
Rarely, but not never. Sonnet left all six correct snippets alone; Haiku flagged public vars holding a site address and a locale as secrets. Both also flagged the fetch status on a proxy that correctly passes the upstream status through, so read a fetch-status finding on a proxy with care.
Why is Turbopack not on the list?
We measured Turbopack breaking an OpenNext build on our own version, but OpenNext now lists Turbopack as supported, and we could not re-check it for current releases. A pitfall we cannot confirm today stays out of the skill.