Agent skill

Cloudflare

by ericrisco in ericrisco/rsc-harness

A skill your agent uses when working on Cloudflare's edge platform — wrangler.jsonc bindings, choosing between D1/KV/R2/Durable Objects/Queues, deploying a Worker or SPA via Static Assets, or…

MITAuto-check passedBackend & APIs

Install Cloudflare

skills CLI
$ npx skills add ericrisco/rsc-harness --skill cloudflare -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ericrisco/rsc-harness cloudflare --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cloudflare .claude/skills/cloudflare && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cloudflare
GitHub stars
156
Token cost
~2.6k tokens
SKILL.md length
899 words
Files
6 (incl. scripts, references)
Skills in repo
229
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when working on Cloudflare's edge platform — wrangler.jsonc bindings, choosing between D1/KV/R2/Durable Objects/Queues, deploying a Worker or SPA via Static Assets, or…

  • Working on Cloudflares edge platform — wrangler.jsonc bindings
  • SKILL.md covers The model in one paragraph, Quick start, wrangler.jsonc anatomy and Pick the right storage primitive, plus 6 more sections
  • Runs Shell scripts from its folder; calls wrangler, npm and npx; needs STRIPE_KEY
  • Choosing between D1/KV/R2/Durable Objects/Queues

What it does

Cloudflare is an agent skill from ericrisco/rsc-harness. Use when working on Cloudflare's edge platform — wrangler.jsonc bindings, choosing between D1/KV/R2/Durable Objects/Queues, deploying a Worker or SPA via Static Assets, or designing around a Workers runtime limit. NOT generic CI/release (that is deployment), NOT Next.js framework wiring (that is nextjs), NOT DNS records (that is domains-dns).

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files, including scripts and reference files (for example `evals/README.md`, `evals/cases.yaml` and `references/storage-primitives.md`).

It sits in Backend & APIs, covering Serverless. It works with Cloudflare, Cloudflare Workers, Next.js and Cloudflare Durable Objects. The repository describes itself as: Your agent invents things because it has no memory, and can't touch your database because it has no arms. rsc is the meta-harness that gives it both, plus the trade to know the… The licence is MIT.

When your agent uses it

  • Working on Cloudflares edge platform — wrangler.jsonc bindings
  • Choosing between D1/KV/R2/Durable Objects/Queues
  • Deploying a Worker
  • SPA via Static Assets

Example prompts

  • “/cloudflare”

Requirements

  • Node.js
  • A Bash shell
  • A credential in STRIPE_KEY

What it can do on your machine

Read from SKILL.md and the folder at commit 92fde8f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • wrangler
    • npm
    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use wrangler, npm and npx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • STRIPE_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cloudflare loads about 2.6k tokens when it runs, and up to ~4.7k if it reads all its reference files. Until then it costs about 90 tokens; SKILL.md has 899 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~90
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from ericrisco/rsc-harness at commit 92fde8f, republished under its MIT licence (© ericrisco). 899 words, ~2,571 tokens.

Download SKILL.mdSave it as .claude/skills/cloudflare/SKILL.md (or your agent's skills folder). This skill also uses 5 other files; get the full folder from GitHub.
name
cloudflare
description
Use when working on Cloudflare's edge platform — wrangler.jsonc bindings, choosing between D1/KV/R2/Durable Objects/Queues, deploying a Worker or SPA via Static Assets, or designing around a Workers runtime limit. NOT generic CI/release (that is `deployment`), NOT Next.js framework wiring (that is `nextjs`), NOT DNS records (that is `domains-dns`).
tags
cloudflare, workers, edge, r2, d1, kv, queues, wrangler, serverless
recommends
deployment, nextjs, domains-dns, postgresdb, redis, secure-coding
origin
risco

Cloudflare Workers & edge primitives

The model in one paragraph

A Worker is a fetch handler that runs at the edge. Everything else — R2, D1, KV, Queues, static assets, Durable Objects — is a binding declared in wrangler.jsonc and reached through env. If a resource is not bound, it is not reachable from your code. There is no connection string and no import of the bucket; you wire it in config, type it on Env, and call env.BINDING. Hold this picture and most "how do I access X" questions answer themselves: declare the binding, redeploy, use env.

Quick start

npm create cloudflare@latest (the C3 scaffolder) bootstraps a Worker or a full framework. Use it — it pins a correct compatibility_date and generates types.

bash
npm create cloudflare@latest my-app          # plain Worker
npm create cloudflare@latest my-app -- --framework=react   # Vite + React SPA, GA plugin
cd my-app
npx wrangler dev          # local edge emulation at http://localhost:8787
npx wrangler deploy       # ships Worker + bound assets in one operation

Wrangler is v4 (an incremental release over the v3 rewrite — same config model, updated deps). Pin it: npx wrangler@4.

wrangler.jsonc anatomy

Config may be wrangler.toml, wrangler.json, or wrangler.jsonc. Prefer jsonc so you can comment bindings. Minimum keys: name, main, compatibility_date.

jsonc
{
  "name": "my-app",
  "main": "src/index.ts",
  // Set to TODAY's date when you start. Why: it pins runtime + flag behavior;
  // bumping it later opts into new defaults (e.g. nodejs_compat auto-enables at 2025-10-01+).
  "compatibility_date": "2026-06-02",
  "compatibility_flags": ["nodejs_compat"],

  // Static Assets — the default way to host a SPA / full-stack app.
  "assets": {
    "directory": "./dist",
    "binding": "ASSETS",                       // env.ASSETS.fetch(request)
    "not_found_handling": "single-page-application"
  },

  // Non-secret config only. Secrets go via `wrangler secret put`, never here.
  "vars": { "API_BASE": "https://api.example.com" },

  "r2_buckets":   [{ "binding": "BUCKET",  "bucket_name": "uploads" }],
  "d1_databases": [{ "binding": "DB", "database_name": "app", "database_id": "<id>" }],
  "kv_namespaces":[{ "binding": "CACHE",  "id": "<namespace-id>" }],
  "queues": {
    "producers": [{ "binding": "JOBS", "queue": "thumbnails" }],
    "consumers": [{ "queue": "thumbnails", "max_batch_size": 10, "max_retries": 3,
                    "dead_letter_queue": "thumbnails-dlq" }]
  }
}

Named environments inherit top-level config and override per env.<name>. See references/wrangler-config.md for the full annotated config, routes, custom domains, and compatibility flags.

Pick the right storage primitive

This is the decision that shapes the architecture. Pick by access pattern and consistency, not by familiarity.

PrimitiveUse forConsistencyHard limitDon't use for
D1Relational app data, per-tenant DBsStrong (single SQLite)10 GB per databaseA single >10 GB monolith; Postgres features (it is SQLite)
KVRead-heavy config, cached lookups, feature flagsEventual (~60s to propagate globally)25 MiB per valueCounters, sessions you read-after-write, anything strongly consistent
R2Files, blobs, uploads, backupsStrong on objectObject storage; no egress feesQuerying/indexing structured data
Durable ObjectsStrongly-consistent coordination, per-entity state, WebSocketsStrong (single-threaded per object)One object = one serialized actorBulk storage; high-fanout reads
QueuesAsync/batch work, decoupling, retriesAt-least-once deliveryBatch ≤100 (default 10)Synchronous request/response

Rule of thumb: need read-after-write? Not KV. Need SQL joins? D1. Need a file? R2. Need a counter or lock? Durable Object. Per-primitive binding config and code, consistency semantics, the complete limits/pricing tables, and Hyperdrive for external Postgres are in references/storage-primitives.md.

Static & full-stack hosting

Workers Static Assets is the recommended way to host SPAs and full-stack apps. The Worker and the assets deploy together.

  • assets.directory — your build output, e.g. ./dist.
  • assets.binding: "ASSETS" — lets the Worker serve files via env.ASSETS.fetch(request).
  • assets.not_found_handling — "single-page-application" (serve index.html on miss, for client-side routing) or "404-page".
  • assets.run_worker_first — run the Worker before serving static assets, e.g. so /api/* hits your handler not a file.

Do not use Workers Sites for new projects — it is deprecated in Wrangler v4 and unsupported by the Cloudflare Vite plugin. Migrating off Pages? Pages still works, but new full-stack work targets Workers; the asset-routing rules and the migration checklist are in references/wrangler-config.md.

Bindings in code

Type every binding on Env. Why: without the interface you lose autocompletion and ship undefined binding bugs to the edge.

ts
export interface Env {
  ASSETS: Fetcher;
  DB: D1Database;
  BUCKET: R2Bucket;
  CACHE: KVNamespace;
  JOBS: Queue<{ key: string }>;
}

export default {
  async fetch(req: Request, env: Env): Promise<Response> {
    const url = new URL(req.url);

    if (url.pathname.startsWith("/api/user")) {
      const row = await env.DB.prepare("SELECT * FROM users WHERE id = ?")
        .bind(url.searchParams.get("id")).first();
      return Response.json(row);
    }
    if (req.method === "PUT" && url.pathname.startsWith("/upload/")) {
      await env.BUCKET.put(url.pathname.slice(8), req.body);
      await env.JOBS.send({ key: url.pathname.slice(8) }); // enqueue thumbnail job
      return new Response("ok", { status: 201 });
    }
    const cached = await env.CACHE.get("config", { cacheTtl: 3600 });
    if (url.pathname === "/config" && cached) return new Response(cached);

    return env.ASSETS.fetch(req); // fall through to the SPA
  },
} satisfies ExportedHandler<Env>;

Secrets, env vars, local dev

bash
wrangler secret put STRIPE_KEY      # encrypted, never in wrangler.jsonc or git
echo "STRIPE_KEY=sk_test_..." >> .dev.vars   # local only — gitignore it
  • Secrets via wrangler secret put only. Why: vars in wrangler.jsonc is committed plaintext.
  • .dev.vars supplies secrets for wrangler dev; add it to .gitignore.
  • vars block = non-secret config (API base URLs, feature flags).
  • wrangler dev emulates bindings locally; add --remote to run against real edge resources.
Show full SKILL.md (368 more words)Show less

Queues wiring

Producer and consumer are both bindings/handlers — same Worker or different Workers.

ts
// Producer (in fetch): enqueue work
await env.JOBS.send({ key });

// Consumer: a queue() handler on the same module
export default {
  async fetch(/* ... */) { /* ... */ },
  async queue(batch: MessageBatch<{ key: string }>, env: Env): Promise<void> {
    for (const msg of batch.messages) {
      try {
        await processThumbnail(msg.key, env); // make this idempotent — delivery is at-least-once
        msg.ack();
      } catch {
        msg.retry();   // up to max_retries (default 3), then dead-letter
      }
    }
  },
};

Defaults: max_batch_size 10 (max 100), max_retries 3, plus max_batch_timeout. Route exhausted messages to a dead_letter_queue. Make consumers idempotent — at-least-once means a message can arrive twice.

Limits that reshape your design

These numbers are architecture inputs, not trivia. Read them before you design.

  • Subrequests per request are capped — fan-out to dozens of origins fails. Batch, cache in KV, or move work to a Queue consumer.
  • CPU time per request is bounded (raised on the paid plan). Long CPU work → Queue + consumer, or Durable Object alarms.
  • KV value ≤ 25 MiB and eventually consistent — large or write-hot data belongs in R2 or D1.
  • D1 ≤ 10 GB per database — shard per tenant/user (D1 is built for many small DBs), don't grow one monolith.
  • Queue batch ≤ 100 — size max_batch_size to your downstream throughput, not the max.

Plan note: the Workers Paid plan is a $5/mo minimum bundling Workers, Pages Functions, KV, Hyperdrive, and Durable Objects; a Free plan exists with reduced limits (D1 free-tier limits enforced since 2025-02-10).

Anti-patterns

Anti-patternWhy it bitesDo instead
KV for sessions / counters you read after writingEventual consistency: a read after a write can be stale up to ~60sD1 (strong) or a Durable Object (per-entity strong)
Growing one D1 database past 10 GBHard cap; you hit a wall mid-scaleShard per tenant/user; large blobs go to R2
Omitting compatibility_dateRuntime/flag behavior drifts; deploys become non-reproducibleSet it to today's date at project start; bump deliberately
Avoiding R2 over egress costR2 has no egress charges — you're optimizing a cost that doesn't existUse R2 for files/blobs; pay only storage + ops
Workers Sites for a new SPADeprecated in Wrangler v4; unsupported by the Vite pluginassets (Static Assets) with not_found_handling
Secrets in vars or committedPlaintext in repo / config = leakwrangler secret put; .dev.vars (gitignored) for local
Treating D1 like a pooled SQL connectionD1 is accessed over HTTP, not a persistent pool — no transactions across requests, no long-held connectionsOne prepared statement per call; batch with db.batch()
Heavy fan-out to many subrequestsHits the subrequest cap and fails the requestCache in KV, batch, or offload to a Queue consumer

© ericrisco, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 5 other files (scripts, references) in skills/cloudflare of ericrisco/rsc-harness.

  • SKILL.md
  • evals/README.md
  • evals/cases.yaml
  • references/storage-primitives.md
  • references/wrangler-config.md
  • scripts/verify.sh

Open the folder on GitHubat commit 92fde8f

Compare with similar skills

Cloudflare next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cloudflare compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cloudflare this skillericrisco/rsc-harness156—~2.6kAutomated safety check: PassMIT
Apikerhodgef/apiker127—~1.4kAutomated safety check: PassMIT
Cloudflare WorkersEpicenterHQ/epicenter4.8k—~576Automated safety check: PassCustom licence
Cloudflare Worker Devcuriositech/some_claude_skills243—~3.4kAutomated safety check: NotesMIT
Cloudflare Experttheneoai/awesome-skills183—~3.5kAutomated safety check: PassMIT
Durable Objectscloudflare/skills3k2 repos~1.5kAutomated safety check: PassApache-2.0

Similar skills

  • Apiker

    hodgef/apiker

    Develop, review, and extend the Apiker library — a framework for building serverless REST APIs on Cloudflare Workers + Durable Objects.

    127 GitHub stars~1.4k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Cloudflare Workers

    EpicenterHQ/epicenter

    Cloudflare Workers patterns for Worker runtime APIs, Durable Objects, KV, R2, D1, Queues, WebSockets, streaming responses, bindings, wrangler configuration, and deployment limits.

    4.8k GitHub stars~576 tokensUpdated today
    Backend & APIsAuto-check passed
  • Cloudflare Worker Dev

    curiositech/some_claude_skills

    Cloudflare Workers, KV, Durable Objects, and edge computing development.

    243 GitHub stars~3.4k tokensUpdated 1 mo ago
    Backend & APIsAuto-check: notes
  • Cloudflare Expert

    theneoai/awesome-skills

    Cloudflare expert: CDN acceleration, WAF and DDoS protection, Zero Trust Access, DNS management, Cloudflare Workers, Pages, and Load Balancing.

    183 GitHub stars~3.5k tokensUpdated 4 mo ago
    Backend & APIsAuto-check passed
  • Durable Objects

    cloudflare/skills

    Official

    Build, debug, or review Cloudflare Durable Objects code for persistent state and coordination.

    3k GitHub starsUsed in 2 repos~1.5k tokens
    Backend & APIsAuto-check passed
  • Durable Objects

    hodgef/apiker

    Create and review Cloudflare Durable Objects. An agent skill from hodgef/apiker.

    127 GitHub starsUsed in 4 repos~1.5k tokens
    Backend & APIsAuto-check passed

More from ericrisco/rsc-harness

All 229 skills in this repo
  • Ab Testing

    ericrisco/rsc-harness

    A skill your agent uses when designing or analyzing a controlled experiment — falsifiable hypothesis, sample size from an MDE, reading significance/CI/power, CUPED, or rescuing tests that won't go…

    156 GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Accessibility

    ericrisco/rsc-harness

    A skill your agent uses when making a web UI conform to WCAG 2.2 Level AA — axe-core or Lighthouse a11y violations, keyboard operability, focus management, ARIA roles/names/live regions, contrast…

    156 GitHub stars~3.4k tokensUpdated today
    Auto-check passed
  • Ads

    ericrisco/rsc-harness

    A skill your agent uses when running or fixing paid acquisition on Google or Meta — campaign structure (Performance Max, Demand Gen, Search, Advantage+), platform-fit creative, budget/scaling rules…

    156 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Agent Eval

    ericrisco/rsc-harness

    A skill your agent uses when measuring whether an LLM or agent system actually got better and gating merges on it: golden sets, fixing an inflated LLM-as-judge, scoring RAG (faithfulness, contextual…

    156 GitHub stars~3.2k tokensUpdated today
    Auto-check passed
  • AI Media

    ericrisco/rsc-harness

    A skill your agent uses when a creative goal must become a finished media file: pick and order generative-media models per modality — AI voiceover, image-to-video clips, score — then glue them with…

    156 GitHub stars~3.3k tokensUpdated today
    Auto-check passed
  • Analytics

    ericrisco/rsc-harness

    A skill your agent uses when instrumenting product or web analytics — GA4/PostHog SDK wiring, event taxonomy, funnels, double-counted events, consent gating, PII scrubbing.

    156 GitHub stars~2.8k tokensUpdated today
    Auto-check passed

Questions about Cloudflare

What does Cloudflare do?

A skill your agent uses when working on Cloudflare's edge platform — wrangler.jsonc bindings, choosing between D1/KV/R2/Durable Objects/Queues, deploying a Worker or SPA via Static Assets, or…. Cloudflare is an agent skill from ericrisco/rsc-harness.jsonc bindings, choosing between D1/KV/R2/Durable Objects/Queues, deploying a Worker or SPA via Static Assets, or designing around a Workers runtime limit.

When should I use Cloudflare?

Cloudflare fits situations like: working on Cloudflares edge platform — wrangler.jsonc bindings; choosing between D1/KV/R2/Durable Objects/Queues; deploying a Worker; SPA via Static Assets.

How do I install Cloudflare in Claude Code?

Run `npx skills add ericrisco/rsc-harness --skill cloudflare -a claude-code`. Or copy the skill folder (skills/cloudflare in ericrisco/rsc-harness) into .claude/skills/cloudflare in your project. Claude Code loads it when a task matches its description.

How do I install Cloudflare in Codex?

Run `npx skills add ericrisco/rsc-harness --skill cloudflare -a codex`. Or copy the skill folder (skills/cloudflare in ericrisco/rsc-harness) into .agents/skills/cloudflare in your project. Codex loads it when a task matches its description.

Can I use Cloudflare in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ericrisco/rsc-harness --skill cloudflare -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cloudflare, .gemini/skills/cloudflare, .github/skills/cloudflare and .opencode/skills/cloudflare in your project.

What does Cloudflare need to run?

Going by SKILL.md and its folder, Cloudflare needs a shell for the scripts in its folder, the command-line tools its instructions call (wrangler, npm and npx) and credentials named STRIPE_KEY. Our summary lists: Node.js; A Bash shell; A credential in STRIPE_KEY.

Does Cloudflare access the network?

SKILL.md contains no URLs. Its commands use npm and npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Cloudflare safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Cloudflare use?

Cloudflare is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cloudflare use?

About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.2k tokens, read only when the agent opens those files.

What are the alternatives to Cloudflare?

Skills that share tags, products or a category with Cloudflare: Apiker (hodgef/apiker, 127 stars), Cloudflare Workers (EpicenterHQ/epicenter, 4.8k stars), Cloudflare Worker Dev (curiositech/some_claude_skills, 243 stars) and Cloudflare Expert (theneoai/awesome-skills, 183 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cloudflare?

ericrisco (a GitHub user) maintains it in ericrisco/rsc-harness, which has 156 GitHub stars. The repository holds 229 skills in this directory. The repository was last updated on October 6, 2026.

Source: ericrisco/rsc-harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.