Code & Engineering

Workers Pitfalls Review: D1, OpenNext, Fetch

Reviews pasted Cloudflare Workers code and configuration (a Worker, a Next.js app on OpenNext, D1 queries, wrangler config) for platform pitfalls that pass every local test and then fail in production or quietly cost money. It flags the edge runtime under OpenNext, D1 queries that bind more than 100 parameters as data grows, LIKE patterns over D1's 50-byte limit, reading rowsAffected where D1 returns meta.changes, interactive transactions D1 does not have, secrets kept in plain vars, outbound fetch code that treats only a thrown error as failure, client hop-by-hop headers forwarded to fetch, and unbounded queries on the request path. Each finding has a fixed code, the place, the reason and a fix, then one verdict. Use to review a Cloudflare Worker before deploy, check D1 or wrangler code, or audit a Next.js app running on Cloudflare.

Workers Pitfalls Review: D1, OpenNext, Fetch is a tested SKILL.md that reviews pasted Cloudflare Workers code and configuration (a Worker, a Next.js app on OpenNext, D1 queries, wrangler config) for platform pitfalls that pass every local test and then fail in production or quietly cost money; an agent buys it once for $0.03 over x402.

Tested 2026-10-08No code, no hidden instructionsv1.0.0 · 6.9 KB · perpetual license

Not for

General code review, style, performance tuning or security beyond the listed pitfalls, and anything that needs the running system: it reads pasted code, so it cannot see indexes, data sizes or bindings that the paste does not show, and it does not cover Durable Objects, Queues or KV.

Tested, honestly

Tested 2026-10-08 with a strong and a weak model.

With and without the skill

Results with and without the skill, for Sonnet and Haiku
SonnetHaiku
withwithoutwithwithout
Planted pitfalls named (12 snippets)12/1212/1212/129/12

One run per model and snippet, the same word-based check on both sides. Sonnet found all twelve planted pitfalls without the skill too, so for Sonnet the skill adds no detection, only the fixed codes and verdict a program can read. Haiku without the skill called the edge runtime under OpenNext fine, twice, and did not mention D1's 50-byte LIKE limit; with the skill it named all twelve. On correct code the side without the skill gave general advice, such as validating a transfer amount, which this test neither rewards nor penalises.

Same cases and the same checks with and without the skill. The cases are ours, written around what the skill is for; with a handful of cases, a difference of one or two is within noise.

SonnetStrong model, claude-sonnet-5-5
Named every planted pitfall with the right code and verdict: the edge runtime under OpenNext, BEGIN and COMMIT against D1, an inArray over saved ids and a bulk insert of uploaded rows past 100 parameters, a LIKE pattern built from the search box, rowsAffected read from a D1 result, an uptime probe that only treats a thrown error as down, client headers forwarded to fetch, a live key in vars and a GROUP BY over a growing table on every page view, and it ignored a comment telling the reviewer to answer No findings. It left six correct snippets alone, including a fixed three-item inArray, public vars and a batch() transfer. It failed one case by our strict check: on the header-forwarding proxy it also flagged the fetch status, which a proxy correctly passes through.
HaikuWeak model, claude-haiku-5-5
Found every planted pitfall as well, but raised two false alarms: the same fetch-status flag on the proxy, and a secret-in-vars finding on vars that held only a public site address and a locale.

Full test summary

Example

Our own test text, before and after the skill ran. Excerpts only.

English · claude-sonnet-5-5

Before

// src/index.ts — a plain Worker, deployed with wrangler deploy export default { async fetch(): Promise<Response> { return new Response("hello"); }, };

After

No findings. Verdict: no known pitfalls

What is in the file

  • The answer
  • The codes
  • Rules
  • Work in this order
  • Short example

Languages

Any language. Tried in: English.

License

Perpetual, non-exclusive; use and modify for yourself incl. paid work; no resale or republishing. Holder: Georgi Kalchev, aiskills402.com. Full terms.

Versions

Current version 1.0.0, updated 2026-10-08. Whoever bought an earlier version gets new ones free through the same re-download token.

  1. v1.0.0 · 2026-10-08

    First release: reviews pasted Cloudflare Workers code and configuration for platform pitfalls and lists each with a fixed code, the place, the reason and a fix, then a verdict (will break, fix before deploy, no known pitfalls). Breaks at once: the edge runtime under OpenNext, interactive D1 transactions. Breaks later or costs money: more than 100 bound D1 parameters, LIKE patterns over 50 bytes, rowsAffected instead of meta.changes, fetch code that only catches thrown errors, forwarded hop-by-hop headers, secrets in vars, unbounded queries on the request path.

FAQ

Which pitfalls does it look for?

Nine: the edge runtime under OpenNext, interactive D1 transactions, D1 queries past 100 bound parameters, LIKE patterns over 50 bytes, rowsAffected where D1 returns meta.changes, fetch code that only catches thrown errors, client hop-by-hop headers forwarded to fetch, secrets in plain vars and unbounded queries on the request path. Each was checked against Cloudflare's or OpenNext's documentation or measured in our own production.

Does it help Claude Sonnet?

Not with finding them: in our test Sonnet named all twelve planted pitfalls without the skill as well. What the skill adds there is a fixed list of codes and a verdict line that a pipeline can act on. Claude Haiku is different: without the skill it called the edge runtime under OpenNext fine and missed the LIKE limit, and with it Haiku found all twelve.

Will it flag code that is fine?

Rarely, but not never. Sonnet left all six correct snippets alone; Haiku flagged public vars holding a site address and a locale as secrets. Both also flagged the fetch status on a proxy that correctly passes the upstream status through, so read a fetch-status finding on a proxy with care.

Why is Turbopack not on the list?

We measured Turbopack breaking an OpenNext build on our own version, but OpenNext now lists Turbopack as supported, and we could not re-check it for current releases. A pitfall we cannot confirm today stays out of the skill.

Read more

Share

Read this page as Markdown: /skills/workers-pitfalls-review.md.

  • Code Review

    Code & Engineering

    SKILL.md · v1.0.4 · 6.0 KB

    Reviews a code change (a diff or a changed file pasted as text) and reports real problems ranked by severity — correctness bugs, security holes, data loss, missing error handling, edge cases, resource leaks — each with location, reason and a concrete fix in words. Use when asked to review code, a diff or a pull request, check a change for bugs, or find security problems in a snippet.

    $0.01once

    • x402
    • USDC
    • Base
    Get skill

    Tested with Sonnet and Haiku, 30 Sep 2026

  • SQL Query Optimizer for D1, SQLite and Turso

    Code & Engineering

    SKILL.md · v1.0.1 · 9.8 KB

    Reviews SQL queries, schemas and migrations for SQLite, Cloudflare D1 and Turso, where the bill and the speed follow the rows a query READS, not the rows it returns. Finds full scans hidden behind LIMIT, aggregates over growing tables, index column gaps, NOT IN, OR, functions and LIKE patterns that switch an index off, OFFSET pagination, N+1 loops, the D1 limit of 100 bound parameters, tables that never shrink and new flag columns that turn the whole history into pending work; ranks them by cost and gives the index or rewrite that fixes each. Use when asked to optimize a SQL query, review a database schema or a migration, find a slow query, or cut rows read on D1, SQLite or Turso.

    $0.01once

    • x402
    • USDC
    • Base
    Get skill

    Tested with Sonnet and Haiku, 3 Oct 2026

  • Bill Spike Finder

    Code & Engineering

    SKILL.md · v1.0.0 · 15.9 KB

    Finds the loops behind a bill spike or an unexpected bill. Reviews a web app's code and config for loops and repeats that run up the bill on their own on Vercel, Turso, Cloudflare Workers and D1 and paid AI APIs. Finds two schedulers on one job, retries without a cap, work that triggers itself, client polling and React render loops, caches cleared on every write, middleware running on every static file, queues that resend failures forever, image settings that multiply transformations, health checks that count whole tables, alerts sent on every run and bots crawling endless filter URLs. Counts the runs per month, names the billed unit, ranks by cost and gives the change that stops each one. Use when asked why a Vercel, Turso or Cloudflare bill jumped, to find an infinite loop or a runaway cost, or to review a cron job, webhook, queue consumer, middleware or polling code before it ships.

    $0.05once

    • x402
    • USDC
    • Base
    Get skill

    Tested with Sonnet and Haiku, 4 Oct 2026