deno-frontend

Warn

Audited by Socket on Feb 16, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

[Skill Scanner] Download or install from free hosting/deployment platform detected No evidence of malicious code or supply-chain deception inside this skill document. The file is instructional documentation for Fresh (Deno) frontend development and its examples align with the stated purpose. Security cautions: (1) Running deno run -Ar (allow-all) and adding external packages (jsr:/ npm:) should only be done from trusted sources; (2) dynamic imports and unimplemented db.query() examples could be sources of path-injection or SQL-injection bugs if developers copy patterns without validation. Overall this skill appears benign but standard operational hygiene is required when following installation and init commands. LLM verification: The skill fragment is internally consistent with its stated purpose of guiding Fresh/Deno frontend assistance and enforcing Fresh 2.x patterns. It does not contain executable code, secrets, or suspicious network activity. While there are mentions of deprecated syntax and scanner-flagged patterns within the documentation, these serve as advisory notes and do not indicate malicious behavior. Overall, the footprint is benign and aligned with its purpose as a knowledge/documentation skill for AI age

Confidence: 90%Severity: 75%
Audit Metadata
Analyzed At
Feb 16, 2026, 01:01 AM
Package URL
pkg:socket/skills-sh/denoland%2Fskills%2Fdeno-frontend%2F@83bec3724454842dde729558cc8be1181ab9c3a0