Cloudflare
hodgef/apiker
Comprehensive Cloudflare platform skill covering Workers, Pages, storage (KV, D1, R2), AI (Workers AI, Vectorize, Agents SDK), feature flags (Flagship), networking (Tunnel, Spectrum), security (WAF…
Cloudflare Workers best practices for production applications.
$ npx skills add cloudflare/skills --skill workers-best-practices -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install cloudflare/skills workers-best-practices --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/cloudflare/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/workers-best-practices .claude/skills/workers-best-practices && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "workers-best-practices" agent skill from https://github.com/cloudflare/skills/tree/main/skills/workers-best-practices into .claude/skills/workers-best-practices/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "workers-best-practices", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/cloudflare/skills/tree/main/skills/workers-best-practicesType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add cloudflare/skills --skill workers-best-practices -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install cloudflare/skills workers-best-practices --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cloudflare/skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/workers-best-practices .agents/skills/workers-best-practices && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "workers-best-practices" agent skill from https://github.com/cloudflare/skills/tree/main/skills/workers-best-practices into .agents/skills/workers-best-practices/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "workers-best-practices", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add cloudflare/skills --skill workers-best-practices -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install cloudflare/skills workers-best-practices --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cloudflare/skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/workers-best-practices .cursor/skills/workers-best-practices && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "workers-best-practices" agent skill from https://github.com/cloudflare/skills/tree/main/skills/workers-best-practices into .cursor/skills/workers-best-practices/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "workers-best-practices", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/cloudflare/skills.git --path skills/workers-best-practices--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add cloudflare/skills --skill workers-best-practices -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install cloudflare/skills workers-best-practices --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cloudflare/skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/workers-best-practices .gemini/skills/workers-best-practices && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "workers-best-practices" agent skill from https://github.com/cloudflare/skills/tree/main/skills/workers-best-practices into .gemini/skills/workers-best-practices/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "workers-best-practices", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install cloudflare/skills workers-best-practicesInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add cloudflare/skills --skill workers-best-practices -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/cloudflare/skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/workers-best-practices .github/skills/workers-best-practices && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "workers-best-practices" agent skill from https://github.com/cloudflare/skills/tree/main/skills/workers-best-practices into .github/skills/workers-best-practices/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "workers-best-practices", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add cloudflare/skills --skill workers-best-practices -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install cloudflare/skills workers-best-practices --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/cloudflare/skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/workers-best-practices .opencode/skills/workers-best-practices && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "workers-best-practices" agent skill from https://github.com/cloudflare/skills/tree/main/skills/workers-best-practices into .opencode/skills/workers-best-practices/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "workers-best-practices", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
workers-best-practicesCloudflare Workers best practices for production applications.
Workers Best Practices is an agent skill from cloudflare/skills, published by the product's own GitHub organization. Cloudflare Workers best practices for production applications. Use when writing, reviewing, or configuring Workers.
Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/configuration.md`, `references/platform-apis.md` and `references/runtime-patterns.md`).
It sits in DevOps & Cloud. It works with Cloudflare Workers and Cloudflare. The repository describes itself as: Skills for teaching agents how to build on Cloudflare. The licence is Apache-2.0.
Read from SKILL.md and the folder at commit 41e0d19. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
wranglerFrom the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
developers.cloudflare.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Workers Best Practices loads about 1.4k tokens when it runs, and up to ~7.2k if it reads all its reference files. Until then it costs about 35 tokens; SKILL.md has 572 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from cloudflare/skills at commit 41e0d19, republished under its Apache-2.0 licence (© cloudflare). 572 words, ~1,387 tokens.
.claude/skills/workers-best-practices/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Your knowledge of Cloudflare Workers APIs, types, and configuration may be outdated. Prefer retrieval over pre-training when writing or reviewing Workers code.
Use the project's installed versions, generated types, and Wrangler compatibility settings as the baseline for existing code. Retrieve relevant Cloudflare documentation to verify API, configuration, runtime behavior, and limit claims.
Read the sections relevant to the task:
| Reference | When to use it |
|---|---|
| Configuration and observability | Compatibility dates, bindings, generated types, secrets, logs, and traces |
| Runtime patterns | Streaming, promise lifetime, request state, service calls, security, and runtime tests |
| Platform API checks | Handler signatures, platform classes, binding access, and serialization |
For missing evidence, consult Workers best practices or find the affected product in the Cloudflare docs directory. Use the installed Wrangler schema for config fields. A newer type package does not supersede the project's configured target.
Use today's date for new Workers. Encourage periodic updates for existing Workers, reviewing compatibility changes and running relevant tests. Assess existing behavior against its configured date and flags; see compatibility guidance.
Enable Workers Logs and Traces when creating or preparing a Worker for production. Set observability.enabled and observability.traces.enabled to true; the top-level setting alone does not enable traces. Use structured JSON logging and configure sampling for the workload. During reviews, flag missing logs or traces. See the configuration example.
| Anti-pattern | Consequence and preferred pattern |
|---|---|
await response.text() or similar buffering on unbounded data | Can exhaust Worker memory; stream large or unbounded bodies. |
| Hardcoded secrets in source or config | Leaks credentials through version control; use Wrangler secrets. |
Math.random() for security-sensitive tokens or IDs | Predictable values; use crypto.randomUUID() or crypto.getRandomValues(). |
Async work started without awaiting, returning, or attaching it to ctx.waitUntil() | Work can be dropped and errors missed; tie it to the request or background-work lifetime. |
| Module-level mutable request state | Leaks data across requests and can cause I/O ownership errors; pass request state explicitly. |
| Cloudflare REST API calls for operations available through Worker bindings | Adds network and authentication overhead; use the available binding. |
ctx.passThroughOnException() used as general error handling | Can conceal Worker failures by forwarding to the origin; use explicit error handling and structured error responses. |
Hand-written Env that duplicates Wrangler bindings | Can drift from configuration; generate binding types with wrangler types. |
| Direct string comparison of secret values | Can expose timing differences; use the Web Crypto comparison pattern. |
Destructuring ctx methods, such as const { waitUntil } = ctx | Loses the receiver; call ctx.waitUntil(...). |
any on Env or handler parameters | Hides binding and handler contract errors; use the project's generated and platform types. |
as unknown as T to force a platform type match | Hides incompatibilities; fix the underlying contract. |
implements used in place of extending a platform base class | Does not inherit runtime behavior, this.ctx, or this.env; use the appropriate base class. |
Unbound env.X in a platform class method | Bindings are available through this.env.X; see binding access patterns. |
| Applying one serialization rule across Queues, Workflow steps, storage, and WebSockets | Can reject valid payloads or accept unsupported ones; check the specific API and encoding. |
Use the project's existing checks for affected Workers behavior: type-check binding or handler contract changes, and run relevant runtime tests for behavior changes. Preserve required repository checks; a narrow edit does not require a full Workers audit.
This skill covers Workers-specific best practices and code review. For related topics:
durable-objects skillwrangler skill© cloudflare, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (references) in skills/workers-best-practices of cloudflare/skills.
Open the folder on GitHubat commit 41e0d19
We found 2 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in cloudflare/skills, which our catalogue first saw on October 7, 2026.
Workers Best Practices next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Workers Best Practices this skillcloudflare/skills | 3k | 2 repos | ~1.4k | Automated safety check: Pass | Apache-2.0 | |
| Cloudflarehodgef/apiker | 127 | 7 repos | ~2.2k | Automated safety check: Pass | MIT | |
| Cloudflaredmmulroy/cloudflare-skill | 728 | — | ~1.6k | Automated safety check: Pass | MIT | |
| Prepare Cloudflare Production DeploymentLubomirGeorgiev/cloudflare-workers-nextjs-saas-template | 786 | — | ~5.9k | Automated safety check: Notes | MIT | |
| Observability Triageevery-app/open-seo | 23k | — | ~1.7k | Automated safety check: Pass | MIT | |
| Workers Best Practiceshodgef/apiker | 127 | 6 repos | ~1.8k | Automated safety check: Pass | MIT |
hodgef/apiker
Comprehensive Cloudflare platform skill covering Workers, Pages, storage (KV, D1, R2), AI (Workers AI, Vectorize, Agents SDK), feature flags (Flagship), networking (Tunnel, Spectrum), security (WAF…
dmmulroy/cloudflare-skill
Comprehensive Cloudflare platform skill covering Workers, Pages, storage (KV, D1, R2), AI (Workers AI, Vectorize, Agents SDK), networking (Tunnel, Spectrum), security (WAF, DDoS), and…
LubomirGeorgiev/cloudflare-workers-nextjs-saas-template
Source-of-truth runbook for preparing this Vinext Cloudflare Workers SaaS template for production deployment.
every-app/open-seo
Triage OpenSEO production errors in Cloudflare Workers Observability — verified query recipes, counting gotchas, and a known-noise filter list applied automatically.
hodgef/apiker
Reviews and authors Cloudflare Workers code against production best practices.
mizchi/skills
Deploy applications and infrastructure to Cloudflare with the cf CLI and typed cloudflare.config.ts.
cloudflare/skills
Set up, repair, or migrate to Cloudflare Turnstile bot verification in an existing frontend and backend, including server-side Siteverify.
cloudflare/skills
Build, migrate, and deploy Next.js apps on Cloudflare Workers with vinext.
cloudflare/skills
Build, debug, or review Cloudflare Agents SDK applications using the agents package.
cloudflare/skills
Build, debug, or review Cloudflare Durable Objects code for persistent state and coordination.
cloudflare/skills
Build or maintain Cloudflare Sandbox apps on @cloudflare/sandbox@next (SDK 1.0 preview).
cloudflare/skills
Assess and plan migrations from existing VPN, SWG, or SASE platforms to Cloudflare One, including policy mapping, parity gaps, and rollout.
Works with
Categories
Cloudflare Workers best practices for production applications. Workers Best Practices is an agent skill from cloudflare/skills, published by the product's own GitHub organization. Cloudflare Workers best practices for production applications.
Workers Best Practices fits situations like: configuring Workers.
Run `npx skills add cloudflare/skills --skill workers-best-practices -a claude-code`. Or copy the skill folder (skills/workers-best-practices in cloudflare/skills) into .claude/skills/workers-best-practices in your project. Claude Code loads it when a task matches its description.
Run `npx skills add cloudflare/skills --skill workers-best-practices -a codex`. Or copy the skill folder (skills/workers-best-practices in cloudflare/skills) into .agents/skills/workers-best-practices in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cloudflare/skills --skill workers-best-practices -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/workers-best-practices, .gemini/skills/workers-best-practices, .github/skills/workers-best-practices and .opencode/skills/workers-best-practices in your project.
Going by SKILL.md and its folder, Workers Best Practices needs the command-line tools its instructions call (wrangler).
SKILL.md names 1 domain. As links in the text: developers.cloudflare.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Workers Best Practices is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.4k tokens (SKILL.md is roughly 5.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 5.8k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Workers Best Practices: Cloudflare (hodgef/apiker, 127 stars), Cloudflare (dmmulroy/cloudflare-skill, 728 stars), Prepare Cloudflare Production Deployment (LubomirGeorgiev/cloudflare-workers-nextjs-saas-template, 786 stars) and Observability Triage (every-app/open-seo, 23k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
cloudflare (a GitHub organization, an official publisher) maintains it in cloudflare/skills, which has 2,999 GitHub stars. The repository holds 16 skills in this directory. The repository was last updated on October 1, 2026.
Source: cloudflare/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.