Skip to content
Back to skills

Cloudflare Platform

ASecurity

Cloudflare Workers, Pages, wrangler bindings, KV/D1/R2 storage and Durable Objects. Use when building or deploying a Worker or Pages site, editing wrangler.toml, or using KV, D1, R2 or Durable Objects.

  • 80 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 3, 2026
ai-agentsjavascriptjavasqlnodenodejsapi

Works with

  • api
  • mcp

Security analysis

A100/100

Scanned October 5, 2026

npx -y skills add monkilabs/opencastle --skill cloudflare-platform --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Cloudflare Platform?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Cloudflare Platform
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/monkilabs-cloudflare-platform/badge)](https://www.skillsdirectory.com/skills/monkilabs-cloudflare-platform)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: cloudflare-platform
description: "Cloudflare Workers, Pages, wrangler bindings, KV/D1/R2 storage and Durable Objects. Use when building or deploying a Worker or Pages site, editing wrangler.toml, or using KV, D1, R2 or Durable Objects."
---

# Cloudflare Platform

## Workers

- V8 isolates, not Node: `process`, `Buffer`, `fs` do not exist unless `compatibility_flags = ["nodejs_compat"]` is set. `compatibility_date` must be set or deploys fail.
- Worker size limit is 3 MB compressed on the Free plan, 10 MB on Paid. Keep dependencies minimal.
- `ctx.waitUntil(promise)` for side effects that must outlive the response (logging, analytics).
- Bindings are reachable only via the handler's `env` argument, and must exist in both `wrangler.toml` and the `Env` interface.
- Durable Objects need `[[durable_objects.bindings]]` **and** a `[[migrations]]` block with `new_classes = ["Counter"]` — the binding alone will not deploy.

## Storage selection

KV: config/sessions/cache, eventually consistent. D1: relational SQLite, strongly consistent. R2: files/blobs, S3-compatible, no egress cost. Durable Objects: coordination, counters, locks, realtime. Queues: async jobs.

Limits: KV value 25MB, key 512 bytes, metadata 1024 bytes, read lag up to 60s. R2 needs multipart upload above 100MB. D1 is SQLite — no MySQL/Postgres-only syntax; always `.bind()` params; `env.DB.batch([...])` collapses round trips.

## Wrangler

- `wrangler secret put NAME [--env staging]` — secrets never live in `wrangler.toml`; local dev uses `.dev.vars`.
- KV bindings need `preview_id` for `wrangler dev --remote`.
- D1 migrations: pass the target explicitly — `wrangler d1 migrations apply <db> --local` for dev, `--remote` for production.
- `wrangler tail` for live production logs; `wrangler deployments list` + `wrangler rollback <version-id>`; `wrangler whoami` to confirm the account.

## MCP

Code Mode exposes exactly two tools: `search` (Cloudflare API spec) and `execute` (JavaScript against the API). ~1k tokens per operation vs ~244k for native tool exposure.

Docs: https://developers.cloudflare.com/

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…