‹ BackHN Continuity

Thread

Cf: The Agentic CLI for the Cloudflare API

171 points · 88 comments · macleos

  1. slowin · · focus · HN ↗
    I don't understand why this is written in Typescript. This is a great example of how agents can write code (I'm sure they wrote `cf`), yet having fundamental computer science knowledge is still critical. Do not force your users to manage the dependencies of your cli. Do write your cli in a compiled language. Understand the reason for those decisions and tell your agents to use the correct architecture.
    1. kelchm · · focus · HN ↗
      Are you really suggesting that the choice to use Typescript wasn't a deliberate one?

      IMO -- it makes total sense within the existing Cloudflare tooling ecosystem.

      1. slowin · · focus · HN ↗
        Whether it was deliberate or not, I do not think it's a good choice. When agents can write in any language, there's no reason to pick the wrong tool for the job. At this point Javascript/Typescript belongs only in the browser. It's the suboptimal choice for every other environment. Especially for a command line tool. Even if the back-end is written in Typescript (also not the best choice imho), the clients need not be in the same language.
        1. chatmasta · · focus · HN ↗
          Typescript and the npm/JS ecosystem may be complex, but you don’t need AGI to figure out how to install a CLI built with TS. My agent can figure out how to install this.
          1. slowin · · focus · HN ↗
            It's not just the complexity. You're also vulnerable to supply chain attacks via NPM. It's also performance as you don't need the entire javascript runtime just for a CLI.
            1. isopede · · focus · HN ↗
              Pretty much every modern language with a package repository is vulnerable to supply chain attacks.

              Are there any languages doing something unique or are especially resilient in this respect?

              1. slowin · · focus · HN ↗
                You can get a binary compiled by the author or a trusted source and none of the dependencies can change out from under you. This isn't possible with an interpreted language where the dependencies are resolved (often from dubious places like npm) at install and update time.
                1. chatmasta · · focus · HN ↗
                  You can write a CLI in typescript and bundle it into a a single JS file. In fact (without looking) I’m sure that’s what Cloudflare is doing here because it’s standard practice.
            2. locknitpicker · · focus · HN ↗
              > It's not just the complexity. You're also vulnerable to supply chain attacks via NPM.

              Oh you mean like the attacks that occur in Rust's cargo?

              <a href="https:&#x2F;&#x2F;blog.rust-lang.org&#x2F;2026&#x2F;08&#x2F;20&#x2F;supply-chain-attack-on-arrayref&#x2F;" rel="nofollow">https:&#x2F;&#x2F;blog.rust-lang.org&#x2F;2026&#x2F;08&#x2F;20&#x2F;supply-chain-attack-on...

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.