Agent skill

Cloudflare R2

by sickn33 in sickn33/agentic-awesome-skills

Manage Cloudflare R2 buckets, lifecycle, and signed URLs. An agent skill from sickn33/agentic-awesome-skills.

MITAuto-check passedBackend & APIs

Install Cloudflare R2

skills CLI
$ npx skills add sickn33/agentic-awesome-skills --skill cloudflare-r2 -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install sickn33/agentic-awesome-skills cloudflare-r2 --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/sickn33/agentic-awesome-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cloudflare-r2 .claude/skills/cloudflare-r2 && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cloudflare-r2
GitHub stars
47k
Used in
2 other repos
Token cost
~2.5k tokens
SKILL.md length
412 words
Files
1
Skills in repo
1,493
Repo updated
First seen
Licence
MIT

At a glance

Manage Cloudflare R2 buckets, lifecycle, and signed URLs. An agent skill from sickn33/agentic-awesome-skills.

  • Works in 4 steps: Go to R2 > Manage R2 API Tokens > Create… → Select permissions: Object Read & Write,… → Scope to specific buckets if possible. → …
  • Low-egress object storage and media delivery
  • SKILL.md covers When to Use, Prerequisites, Bucket Management with Wrangler and S3-Compatible API Access, plus 7 more sections
  • Calls npx, aws and curl; reaches api.cloudflare.com; needs R2_ACCESS_KEY and R2_SECRET_KEY

What it does

Cloudflare R2 is an agent skill from sickn33/agentic-awesome-skills. Manage Cloudflare R2 buckets, lifecycle, and signed URLs. Use for low-egress object storage and media delivery.

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Requires the relevant OS/platform tooling and privileged access where noted. Docs-only; helper scripts and templates not bundled.

It sits in Backend & APIs, covering File uploads and storage. It works with Cloudflare R2, Cloudflare Workers and Cloudflare. The repository describes itself as: AAS Core is the local, agent-first control plane for complete catalog discovery, agent-owned selection, stack validation, and planning, backed by 2,400+ agentic skills. Includes… The licence is MIT.

When your agent uses it

  • Low-egress object storage and media delivery
  • Tasks that involve File uploads and storage

Example prompts

  • “/cloudflare-r2”

Requirements

  • Python 3
  • Node.js
  • A credential in CLOUDFLARE_API_TOKEN
  • A credential in R2_ACCESS_KEY
  • Compatibility (from SKILL.md): Requires the relevant OS/platform tooling and privileged access where noted. Docs-only; helper scripts and templates not bundled.

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Go to R2 > Manage R2 API Tokens > Create API token.
  2. Select permissions: Object Read & Write, or Object Read only.
  3. Scope to specific buckets if possible.
  4. Save the Access Key ID and Secret Access Key.

What it can do on your machine

Read from SKILL.md and the folder at commit 680176d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npx
    • aws
    • curl
    • npm
    • wrangler

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • api.cloudflare.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • R2_ACCESS_KEY
    • R2_SECRET_KEY
    • CLOUDFLARE_API_TOKEN
    • CF_API_TOKEN

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Requires the relevant OS/platform tooling and privileged access where noted. Docs-only; helper scripts and templates not bundled.

    From compatibility in the SKILL.md frontmatter.

Context cost

Cloudflare R2 loads about 2.5k tokens when it runs. Until then it costs about 31 tokens; SKILL.md has 412 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~31
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from sickn33/agentic-awesome-skills at commit 680176d, republished under its MIT licence (© sickn33). 412 words, ~2,534 tokens.

Download SKILL.mdSave it as .claude/skills/cloudflare-r2/SKILL.md (or your agent's skills folder).
name
cloudflare-r2
description
Manage Cloudflare R2 buckets, lifecycle, and signed URLs. Use for low-egress object storage and media delivery.
compatibility
Requires the relevant OS/platform tooling and privileged access where noted. Docs-only; helper scripts and templates not bundled.
category
devops
risk
critical
source
https://github.com/BagelHole/DevOps-Security-Agent-Skills
source_repo
BagelHole/DevOps-Security-Agent-Skills
source_type
community
date_added
2026-09-20
license
MIT
license_source
https://github.com/BagelHole/DevOps-Security-Agent-Skills/blob/main/LICENSE
metadata.author
devops-skills
metadata.version
1.0

Cloudflare R2

S3-compatible object storage with zero egress fees, built on Cloudflare's global network.

When to Use

  • Storing user uploads, media files, backups, or static assets.
  • Replacing AWS S3 to eliminate egress costs for read-heavy workloads.
  • Serving files at the edge via Workers or public bucket access.
  • Building multi-cloud storage that avoids vendor lock-in (S3 API compatible).
  • Storing ML model artifacts, training data, or inference results.

Prerequisites

  • Cloudflare account with R2 enabled (dashboard > R2 > subscribe).
  • Wrangler CLI v3+ installed: npm install -g wrangler.
  • Authenticated via wrangler login or CLOUDFLARE_API_TOKEN.
  • For S3 API access: R2 API token created under R2 > Manage R2 API Tokens.

Bucket Management with Wrangler

Create and List Buckets
bash
# Create a new bucket
npx wrangler r2 bucket create app-assets

# Create a bucket in a specific region (hint for data locality)
npx wrangler r2 bucket create eu-uploads --location=eu

# List all buckets
npx wrangler r2 bucket list

# Delete an empty bucket
npx wrangler r2 bucket delete old-bucket
Object Operations
bash
# Upload a single file
npx wrangler r2 object put app-assets/images/logo.png --file=./logo.png

# Upload with content type
npx wrangler r2 object put app-assets/data/report.json \
  --file=./report.json \
  --content-type="application/json"

# Download an object
npx wrangler r2 object get app-assets/images/logo.png --file=./downloaded-logo.png

# Delete an object
npx wrangler r2 object delete app-assets/images/old-logo.png

# Get object metadata
npx wrangler r2 object head app-assets/images/logo.png

S3-Compatible API Access

R2 supports the S3 API, so existing tools (AWS CLI, boto3, s3cmd) work out of the box.

Generate R2 API Tokens
  1. Go to R2 > Manage R2 API Tokens > Create API token.
  2. Select permissions: Object Read & Write, or Object Read only.
  3. Scope to specific buckets if possible.
  4. Save the Access Key ID and Secret Access Key.
AWS CLI Configuration
bash
# Configure a named profile for R2
aws configure --profile r2
# Access Key ID: <your-r2-access-key>
# Secret Access Key: <your-r2-secret-key>
# Region: auto
# Output: json

# Use the R2 endpoint
export R2_ENDPOINT="https://<ACCOUNT_ID>.r2.cloudflarestorage.com"

# List buckets
aws s3 ls --endpoint-url=$R2_ENDPOINT --profile=r2

# Sync a directory
aws s3 sync ./dist s3://app-assets/static/ \
  --endpoint-url=$R2_ENDPOINT \
  --profile=r2

# Copy a file
aws s3 cp ./backup.tar.gz s3://app-assets/backups/backup-$(date +%Y%m%d).tar.gz \
  --endpoint-url=$R2_ENDPOINT \
  --profile=r2

# List objects with prefix
aws s3 ls s3://app-assets/images/ \
  --endpoint-url=$R2_ENDPOINT \
  --profile=r2

# Remove objects by prefix
aws s3 rm s3://app-assets/tmp/ --recursive \
  --endpoint-url=$R2_ENDPOINT \
  --profile=r2
Python boto3 Client
python
import boto3

s3 = boto3.client(
    "s3",
    endpoint_url="https://<ACCOUNT_ID>.r2.cloudflarestorage.com",
    aws_access_key_id="<R2_ACCESS_KEY>",
    aws_secret_access_key="<R2_SECRET_KEY>",
    region_name="auto",
)

# Upload file
s3.upload_file("./report.pdf", "app-assets", "reports/report.pdf")

# Generate presigned URL (valid for 1 hour)
url = s3.generate_presigned_url(
    "get_object",
    Params={"Bucket": "app-assets", "Key": "reports/report.pdf"},
    ExpiresIn=3600,
)
print(url)

# List objects
response = s3.list_objects_v2(Bucket="app-assets", Prefix="images/", MaxKeys=100)
for obj in response.get("Contents", []):
    print(f"{obj['Key']} - {obj['Size']} bytes")

Worker Bindings

Bind R2 buckets to Workers or Pages Functions for server-side access without API tokens.

Wrangler Configuration
toml
# wrangler.toml
name = "asset-worker"
main = "src/index.ts"
compatibility_date = "2024-09-01"

[[r2_buckets]]
binding = "ASSETS"
bucket_name = "app-assets"

[[r2_buckets]]
binding = "UPLOADS"
bucket_name = "user-uploads"
Worker with R2 Operations
typescript
// src/index.ts
interface Env {
  ASSETS: R2Bucket;
  UPLOADS: R2Bucket;
}

export default {
  async fetch(request: Request, env: Env): Promise<Response> {
    const url = new URL(request.url);

    // GET — serve file from R2
    if (request.method === "GET") {
      const key = url.pathname.slice(1); // strip leading /
      const object = await env.ASSETS.get(key);

      if (!object) {
        return new Response("Not Found", { status: 404 });
      }

      const headers = new Headers();
      object.writeHttpMetadata(headers);
      headers.set("etag", object.httpEtag);
      headers.set("cache-control", "public, max-age=86400");

      return new Response(object.body, { headers });
    }

    // PUT — upload file to R2
    if (request.method === "PUT") {
      const key = url.pathname.slice(1);
      const contentType = request.headers.get("content-type") || "application/octet-stream";

      await env.UPLOADS.put(key, request.body, {
        httpMetadata: { contentType },
        customMetadata: { uploadedAt: new Date().toISOString() },
      });

      return new Response(JSON.stringify({ key, status: "uploaded" }), {
        headers: { "Content-Type": "application/json" },
      });
    }

    // DELETE — remove file
    if (request.method === "DELETE") {
      const key = url.pathname.slice(1);
      await env.UPLOADS.delete(key);
      return new Response(null, { status: 204 });
    }

    return new Response("Method Not Allowed", { status: 405 });
  },
};
Presigned URL Generation in a Worker
typescript
// Generate time-limited signed URLs using Workers
import { AwsClient } from "aws4fetch";

interface Env {
  R2_ACCESS_KEY: string;
  R2_SECRET_KEY: string;
  R2_ACCOUNT_ID: string;
}

export default {
  async fetch(request: Request, env: Env): Promise<Response> {
    const aws = new AwsClient({
      accessKeyId: env.R2_ACCESS_KEY,
      secretAccessKey: env.R2_SECRET_KEY,
    });

    const url = new URL(request.url);
    const key = url.searchParams.get("key");
    if (!key) return new Response("Missing key", { status: 400 });

    const r2Url = `https://${env.R2_ACCOUNT_ID}.r2.cloudflarestorage.com/app-assets/${key}`;

    const signed = await aws.sign(new Request(r2Url), {
      aws: { signQuery: true },
    });

    return Response.json({ url: signed.url });
  },
};

Public Bucket Access

Enable public access to serve files directly without a Worker.

  1. Go to R2 > bucket > Settings > Public access.
  2. Enable and set a custom domain (e.g., assets.example.com).
  3. Objects are accessible at https://assets.example.com/<key>.
bash
# Or enable via the r2.dev subdomain (for testing)
# Bucket Settings > R2.dev subdomain > Allow Access
# URL: https://pub-<hash>.r2.dev/<key>
Show full SKILL.md (167 more words)Show less

Lifecycle Rules

Configure automatic object expiration or transition.

bash
# Set lifecycle rules via the Cloudflare dashboard:
# R2 > bucket > Settings > Object lifecycle rules

# Or via API
curl -X PUT "https://api.cloudflare.com/client/v4/accounts/$ACCOUNT_ID/r2/buckets/app-assets/lifecycle" \
  -H "Authorization: Bearer $CF_API_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "rules": [
      {
        "id": "expire-tmp-files",
        "enabled": true,
        "conditions": { "prefix": "tmp/" },
        "actions": { "deleteObject": { "daysAfterCreationDate": 7 } }
      },
      {
        "id": "expire-old-logs",
        "enabled": true,
        "conditions": { "prefix": "logs/" },
        "actions": { "deleteObject": { "daysAfterCreationDate": 90 } }
      }
    ]
  }'

CORS Configuration

bash
# Set CORS policy for browser-based uploads
curl -X PUT "https://api.cloudflare.com/client/v4/accounts/$ACCOUNT_ID/r2/buckets/app-assets/cors" \
  -H "Authorization: Bearer $CF_API_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "corsRules": [
      {
        "allowedOrigins": ["https://example.com"],
        "allowedMethods": ["GET", "PUT", "HEAD"],
        "allowedHeaders": ["Content-Type", "Authorization"],
        "maxAgeSeconds": 3600
      }
    ]
  }'

Troubleshooting

SymptomCauseFix
NoSuchBucket error via S3 APIWrong endpoint or bucket nameVerify endpoint is https://<ACCOUNT_ID>.r2.cloudflarestorage.com
SignatureDoesNotMatchIncorrect secret key or endpoint mismatchRegenerate R2 API token; ensure region is auto
Uploads succeed but GET returns 404Key path mismatch (leading slash)R2 keys should not start with /
Slow uploads for large filesSingle-stream uploadUse multipart upload; set --expected-size with wrangler
CORS errors in browserMissing CORS config on bucketAdd CORS rules for your origin domain
Worker binding returns undefinedwrangler.toml binding name mismatchVerify binding name matches Env interface property
Public access returns 403Public access not enabledEnable in bucket Settings > Public access
  • cloudflare-workers (cloudflare-workers) - Signed URL generation and edge file serving
  • cloudflare-pages (cloudflare-pages) - Pages Functions with R2 bindings
  • cdn-setup (cdn-setup) - CDN configuration for asset delivery

Limitations

  • Infrastructure commands can disrupt services: confirm target host/scope and have backups/snapshots before mutating state.
  • Docs-only import: upstream scripts and templates not bundled.

© sickn33, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/cloudflare-r2 of sickn33/agentic-awesome-skills.

Open the folder on GitHubat commit 680176d

Used in 2 other repositories

We found 6 copies of this SKILL.md (exact, near-identical or edited) in other folders, from 2 other GitHub owners. This page covers the copy in sickn33/agentic-awesome-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Cloudflare R2 next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cloudflare R2 compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cloudflare R2 this skillsickn33/agentic-awesome-skills47k2 repos~2.5kAutomated safety check: PassMIT
Cloudflare R2einverne/dotfiles121—~2.8kAutomated safety check: PassGPL-3.0
Basincloudflare/skills3k1 repos~684Automated safety check: PassApache-2.0
Cloudflare 3sundial-org/awesome-openclaw-skills663—~1.5kAutomated safety check: PassNone
Durable Objectscloudflare/skills3k2 repos~1.5kAutomated safety check: PassApache-2.0
Durable Objectshodgef/apiker1274 repos~1.5kAutomated safety check: PassMIT

Similar skills

  • Cloudflare R2

    einverne/dotfiles

    Guide for implementing Cloudflare R2 - S3-compatible object storage with zero egress fees.

    121 GitHub stars~2.8k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Basin

    cloudflare/skills

    Official

    Build and troubleshoot Cloudflare Basin analytics workflows with Basin Pipelines, Basin Catalog, and Basin SQL.

    3k GitHub starsUsed in 1 repo~684 tokens
    DatabasesAuto-check passed
  • Cloudflare 3

    sundial-org/awesome-openclaw-skills

    Manage Cloudflare Workers, KV, D1, R2, and secrets using the Wrangler CLI.

    663 GitHub stars~1.5k tokensUpdated 7 mo ago
    DevOps & CloudAuto-check passed
  • Durable Objects

    cloudflare/skills

    Official

    Build, debug, or review Cloudflare Durable Objects code for persistent state and coordination.

    3k GitHub starsUsed in 2 repos~1.5k tokens
    Backend & APIsAuto-check passed
  • Durable Objects

    hodgef/apiker

    Create and review Cloudflare Durable Objects. An agent skill from hodgef/apiker.

    127 GitHub starsUsed in 4 repos~1.5k tokens
    Backend & APIsAuto-check passed
  • S3 Explore

    duckdb/duckdb-skills

    Official

    Explore and query data on S3, Cloudflare R2, GCS, MinIO, or any S3-compatible storage.

    604 GitHub starsUsed in 1 repo~848 tokens
    Backend & APIsAuto-check: notes

More from sickn33/agentic-awesome-skills

All 1,493 skills in this repo
  • Liuguang Banlan UI

    sickn33/agentic-awesome-skills

    Implements an interface in one of two named color modes, iridescent white or colorful black, from a parameterized starter that reports measured color intensity.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • User Thoughts Memory

    sickn33/agentic-awesome-skills

    Saves a user's project decisions, rules and preferences into a project-local mdbase so later sessions and other agents can recover the intent.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    Auto-check passed
  • Using LWC Memory and Graphs

    sickn33/agentic-awesome-skills

    Keeps project decisions, research and verified results available across coding-agent sessions through LWC memory, a document Wiki graph and a CodeGraph code index.

    47k GitHub starsUsed in 1 repo~2k tokens
    Auto-check passed
  • Find Complementary Founders

    sickn33/agentic-awesome-skills

    Guides an agent through assessing its own owner for cofounder fit, publishing an approved profile, and ranking complementary profiles other agents published for their owners.

    47k GitHub starsUsed in 1 repo~4.8k tokens
    Auto-check passed
  • Whatsapp Cloud API

    sickn33/agentic-awesome-skills

    Integracao com WhatsApp Business Cloud API (Meta). An agent skill from sickn33/agentic-awesome-skills.

    47k GitHub starsUsed in 2 repos~4.5k tokens
    Auto-check passed
  • Cline Pilot

    sickn33/agentic-awesome-skills

    Acts as a proxy for the Cline CLI, dispatching coding tasks one at a time, monitoring runs by hard evidence, relaying decisions to you and learning per-project preferences.

    47k GitHub starsUsed in 1 repo~4.6k tokens
    Auto-check passed

Categories

Questions about Cloudflare R2

What does Cloudflare R2 do?

Manage Cloudflare R2 buckets, lifecycle, and signed URLs. An agent skill from sickn33/agentic-awesome-skills. Cloudflare R2 is an agent skill from sickn33/agentic-awesome-skills. Manage Cloudflare R2 buckets, lifecycle, and signed URLs.

When should I use Cloudflare R2?

Cloudflare R2 fits situations like: low-egress object storage and media delivery; tasks that involve File uploads and storage.

How do I install Cloudflare R2 in Claude Code?

Run `npx skills add sickn33/agentic-awesome-skills --skill cloudflare-r2 -a claude-code`. Or copy the skill folder (skills/cloudflare-r2 in sickn33/agentic-awesome-skills) into .claude/skills/cloudflare-r2 in your project. Claude Code loads it when a task matches its description.

How do I install Cloudflare R2 in Codex?

Run `npx skills add sickn33/agentic-awesome-skills --skill cloudflare-r2 -a codex`. Or copy the skill folder (skills/cloudflare-r2 in sickn33/agentic-awesome-skills) into .agents/skills/cloudflare-r2 in your project. Codex loads it when a task matches its description.

Can I use Cloudflare R2 in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add sickn33/agentic-awesome-skills --skill cloudflare-r2 -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cloudflare-r2, .gemini/skills/cloudflare-r2, .github/skills/cloudflare-r2 and .opencode/skills/cloudflare-r2 in your project.

What does Cloudflare R2 need to run?

Going by SKILL.md and its folder, Cloudflare R2 needs the command-line tools its instructions call (npx, aws, curl, npm and wrangler) and credentials named R2_ACCESS_KEY, R2_SECRET_KEY, CLOUDFLARE_API_TOKEN and CF_API_TOKEN. Our summary lists: Python 3; Node.js; A credential in CLOUDFLARE_API_TOKEN; A credential in R2_ACCESS_KEY. Compatibility (from SKILL.md): Requires the relevant OS/platform tooling and privileged access where noted. Docs-only; helper scripts and templates not bundled..

Does Cloudflare R2 access the network?

SKILL.md names 1 domain. In commands or code: api.cloudflare.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Cloudflare R2 safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Cloudflare R2 use?

Cloudflare R2 is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cloudflare R2 use?

About 2.5k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Cloudflare R2?

Skills that share tags, products or a category with Cloudflare R2: Cloudflare R2 (einverne/dotfiles, 121 stars), Basin (cloudflare/skills, 3k stars), Cloudflare 3 (sundial-org/awesome-openclaw-skills, 663 stars) and Durable Objects (cloudflare/skills, 3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cloudflare R2?

sickn33 (a GitHub user) maintains it in sickn33/agentic-awesome-skills, which has 47,379 GitHub stars. The repository holds 1,493 skills in this directory. The repository was last updated on October 9, 2026.

Source: sickn33/agentic-awesome-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.