I don't understand why this is written in Typescript. This is a great example of how agents can write code (I'm sure they wrote `cf`), yet having fundamental computer science knowledge is still critical. Do not force your users to manage the dependencies of your cli. Do write your cli in a compiled language. Understand the reason for those decisions and tell your agents to use the correct architecture.
Whether it was deliberate or not, I do not think it's a good choice. When agents can write in any language, there's no reason to pick the wrong tool for the job. At this point Javascript/Typescript belongs only in the browser. It's the suboptimal choice for every other environment. Especially for a command line tool. Even if the back-end is written in Typescript (also not the best choice imho), the clients need not be in the same language.
Typescript and the npm/JS ecosystem may be complex, but you don’t need AGI to figure out how to install a CLI built with TS. My agent can figure out how to install this.
It's not just the complexity. You're also vulnerable to supply chain attacks via NPM. It's also performance as you don't need the entire javascript runtime just for a CLI.
slowin · · focus · HN ↗
kelchm · · focus · HN ↗
IMO -- it makes total sense within the existing Cloudflare tooling ecosystem.
slowin · · focus · HN ↗
chatmasta · · focus · HN ↗
slowin · · focus · HN ↗
locknitpicker · · focus · HN ↗
Oh you mean like the attacks that occur in Rust's cargo?
<a href="https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref/" rel="nofollow">https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on...