deno-expert
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEMETADATA_POISONINGCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [METADATA_POISONING]: The skill metadata identifies the author as 'denoland', which differs from the provided author information 'midudev'. This creates a minor inconsistency regarding the skill's official origin versus its actual developer.- [COMMAND_EXECUTION]: The skill includes documentation for powerful command-line operations, specifically 'deno run -Ar jsr:@fresh/init'. The '-A' flag (equivalent to --allow-all) grants full permissions to the process for networking, file access, and environment variables. While standard for project initialization, users should be aware that this bypasses Deno's default sandbox security.- [EXTERNAL_DOWNLOADS]: The skill promotes the use of the JSR and NPM registries for dependency management and includes commands that fetch remote code, such as 'deno add' and 'deno upgrade'.- [INDIRECT_PROMPT_INJECTION]: The skill is designed to perform code reviews and debugging on user-supplied Deno and Fresh source code. This creates an attack surface where malicious instructions embedded in the code snippets could attempt to influence the agent's behavior.
- Ingestion points: User-provided source code files and snippets provided during review or debugging requests.
- Boundary markers: The instructions do not define explicit delimiters or 'ignore' commands to isolate user code from the agent's primary instructions.
- Capability inventory: The skill has access to shell command suggestions for project management and deployment.
- Sanitization: No specific input validation or sanitization of user-provided code is mentioned.
Audit Metadata