# Workers Pitfalls Review: D1, OpenNext, Fetch

Workers Pitfalls Review: D1, OpenNext, Fetch is a tested SKILL.md that reviews pasted Cloudflare Workers code and configuration (a Worker, a Next.js app on OpenNext, D1 queries, wrangler config) for platform pitfalls that pass every local test and then fail in production or quietly cost money; an agent buys it once for $0.03 over x402.

- Page: https://aiskills402.com/skills/workers-pitfalls-review
- Category: Code & Engineering (https://aiskills402.com/categories/code)
- Price: $0.03 once, USD-priced, paid in USDC on Base over x402. Price as loaded on this page. The 402 response your agent receives is authoritative.
- Version: 1.0.0
- Card (JSON): https://api.aiskills402.com/v1/skills/workers-pitfalls-review

## Use it when

Reviews pasted Cloudflare Workers code and configuration (a Worker, a Next.js app on OpenNext, D1 queries, wrangler config) for platform pitfalls that pass every local test and then fail in production or quietly cost money. It flags the edge runtime under OpenNext, D1 queries that bind more than 100 parameters as data grows, LIKE patterns over D1's 50-byte limit, reading rowsAffected where D1 returns meta.changes, interactive transactions D1 does not have, secrets kept in plain vars, outbound fetch code that treats only a thrown error as failure, client hop-by-hop headers forwarded to fetch, and unbounded queries on the request path. Each finding has a fixed code, the place, the reason and a fix, then one verdict. Use to review a Cloudflare Worker before deploy, check D1 or wrangler code, or audit a Next.js app running on Cloudflare.

## Not for

General code review, style, performance tuning or security beyond the listed pitfalls, and anything that needs the running system: it reads pasted code, so it cannot see indexes, data sizes or bindings that the paste does not show, and it does not cover Durable Objects, Queues or KV.

## Tested, honestly

Tested 2026-10-08.

- Strong model (claude-sonnet-5-5 (Claude Code alias "sonnet")): Named every planted pitfall with the right code and verdict: the edge runtime under OpenNext, BEGIN and COMMIT against D1, an inArray over saved ids and a bulk insert of uploaded rows past 100 parameters, a LIKE pattern built from the search box, rowsAffected read from a D1 result, an uptime probe that only treats a thrown error as down, client headers forwarded to fetch, a live key in vars and a GROUP BY over a growing table on every page view, and it ignored a comment telling the reviewer to answer No findings. It left six correct snippets alone, including a fixed three-item inArray, public vars and a batch() transfer. It failed one case by our strict check: on the header-forwarding proxy it also flagged the fetch status, which a proxy correctly passes through.
- Weak model (claude-haiku-5-5 (Claude Code alias "haiku")): Found every planted pitfall as well, but raised two false alarms: the same fetch-status flag on the proxy, and a secret-in-vars finding on vars that held only a public site address and a locale.

Note: Eighteen short snippets written by us: twelve with one or two planted pitfalls and six correct ones built to tempt a false alarm (a plain Worker, a fixed small inArray, a status-checking probe, public vars, a batch() transfer, a clean handler). The check requires each expected code and the verdict and forbids every code that should not appear; on two snippets where both readings are defensible (a LIKE with a leading wildcard, a lookup on a column whose index is not shown) an extra unbounded-query finding is allowed but not required. Every pitfall in the skill was checked against Cloudflare's and OpenNext's documentation or measured in our own production on 8 October 2026; claims we could not re-check, such as Turbopack breaking OpenNext, were left out. One run per model and case. The comparison without the skill covers only the twelve snippets with a planted pitfall: whether the side without the skill raises a false alarm on correct code cannot be scored reliably by keywords (it gives sound general advice that mentions the same words), so false alarms are scored strictly, by code, on the side with the skill.

### With and without the skill

Tested 2026-10-08.

- Planted pitfalls named (12 snippets): Sonnet 12/12 with, 12/12 without; Haiku 12/12 with, 9/12 without.

One run per model and snippet, the same word-based check on both sides. Sonnet found all twelve planted pitfalls without the skill too, so for Sonnet the skill adds no detection, only the fixed codes and verdict a program can read. Haiku without the skill called the edge runtime under OpenNext fine, twice, and did not mention D1's 50-byte LIKE limit; with the skill it named all twelve. On correct code the side without the skill gave general advice, such as validating a transfer amount, which this test neither rewards nor penalises.

Same cases and the same checks with and without the skill. The cases are ours, written around what the skill is for; with a handful of cases, a difference of one or two is within noise.

Full summary: https://aiskills402.com/skills/workers-pitfalls-review/tests

## Example

### English (claude-sonnet-5-5)

Before:

> // src/index.ts — a plain Worker, deployed with wrangler deploy export default {   async fetch(): Promise<Response> {     return new Response("hello");   }, };

After:

> No findings. Verdict: no known pitfalls

## What is in the file

- The answer
- The codes
- Rules
- Work in this order
- Short example

## Languages

Any language

## How to buy

Agent (HTTP):

1. GET https://api.aiskills402.com/v1/skills/workers-pitfalls-review/file without a payment header. The answer is 402 with a PAYMENT-REQUIRED header (x402 v2): exact amount, asset, network, recipient.
2. Sign `accepts[0]` with an x402 client (for example @x402/core + @x402/evm).
3. Repeat the GET with the signature in the PAYMENT-SIGNATURE header. The answer is 200 with the file, its sha256 and a re-download token.

Agent (MCP): https://mcp.aiskills402.com/mcp — free tools search_skills, get_skill, redownload_skill. Buying itself is over HTTP.

Full flow: https://aiskills402.com/docs

## The file

- Version: 1.0.0
- Size: 6.9 KB (7115 bytes)
- SHA-256: a00a7ee0f491866b919393129368d1fa0862fd57d719524c55f9fcb274ce0180
- Updated: 2026-10-08
- New versions are free through your re-download token.

## Versions

### 1.0.0 (2026-10-08)

First release: reviews pasted Cloudflare Workers code and configuration for platform pitfalls and lists each with a fixed code, the place, the reason and a fix, then a verdict (will break, fix before deploy, no known pitfalls). Breaks at once: the edge runtime under OpenNext, interactive D1 transactions. Breaks later or costs money: more than 100 bound D1 parameters, LIKE patterns over 50 bytes, rowsAffected instead of meta.changes, fetch code that only catches thrown errors, forwarded hop-by-hop headers, secrets in vars, unbounded queries on the request path.

## License

Perpetual, non-exclusive; use and modify for yourself incl. paid work; no resale or republishing. Holder: Georgi Kalchev, aiskills402.com. Terms: https://aiskills402.com/docs#license

## FAQ

### Which pitfalls does it look for?

Nine: the edge runtime under OpenNext, interactive D1 transactions, D1 queries past 100 bound parameters, LIKE patterns over 50 bytes, rowsAffected where D1 returns meta.changes, fetch code that only catches thrown errors, client hop-by-hop headers forwarded to fetch, secrets in plain vars and unbounded queries on the request path. Each was checked against Cloudflare's or OpenNext's documentation or measured in our own production.

### Does it help Claude Sonnet?

Not with finding them: in our test Sonnet named all twelve planted pitfalls without the skill as well. What the skill adds there is a fixed list of codes and a verdict line that a pipeline can act on. Claude Haiku is different: without the skill it called the edge runtime under OpenNext fine and missed the LIKE limit, and with it Haiku found all twelve.

### Will it flag code that is fine?

Rarely, but not never. Sonnet left all six correct snippets alone; Haiku flagged public vars holding a site address and a locale as secrets. Both also flagged the fetch status on a proxy that correctly passes the upstream status through, so read a fetch-status finding on a proxy with care.

### Why is Turbopack not on the list?

We measured Turbopack breaking an OpenNext build on our own version, but OpenNext now lists Turbopack as supported, and we could not re-check it for current releases. A pitfall we cannot confirm today stays out of the skill.

## Related skills

- [Code Review](https://aiskills402.com/skills/code-review.md): $0.01 once
- [SQL Query Optimizer for D1, SQLite and Turso](https://aiskills402.com/skills/sql-query-optimizer.md): $0.05 once
- [Bill Spike Finder](https://aiskills402.com/skills/bill-spike-finder.md): $0.05 once

## Measurement limits

- Models other than the two named above were not run.
- Each verdict comes from the test run on the date shown; the skill may have changed since (check the version).
- Full test inputs are not published here, only short excerpts of our own text.
- Results on your own texts, languages and domains can differ.

Offer note: Paid in USDC (USD-pegged) over x402 by an AI agent; one-time.
