deno-frontend

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references several external resources and initialization scripts.
    • Fetches the project initializer from the official Deno JSR registry (jsr:@fresh/init).
    • References documentation from the official Fresh framework domain (fresh.deno.dev).
    • Uses a placeholder API for demonstration purposes (jsonplaceholder.typicode.com).
  • [REMOTE_CODE_EXECUTION]: The skill provides instructions for initializing new projects.
    • Executes the Fresh initializer using deno run -Ar jsr:@fresh/init. While the -A flag grants full permissions, this is the standard and official installation method for the Fresh framework in the Deno ecosystem.
  • [DYNAMIC_EXECUTION]: The skill demonstrates standard Fresh 2.x routing logic.
    • Uses dynamic import() statements in the fsRoutes configuration to load island and route components based on the project's file structure. This is an architectural requirement for the framework's file-based routing and does not incorporate untrusted external input.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines templates for handling web requests and route parameters.
    • Ingestion points: Handles external data through ctx.params and ctx.req in route handlers.
    • Boundary markers: Not applicable to these code templates.
    • Capability inventory: Includes filesystem writes (generating project files) and network operations (fetching data in handlers).
    • Sanitization: Encourages the use of serializable props for client-side islands, which acts as a data boundary. The patterns shown are standard for web development and do not introduce unusual risk vectors.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 11:19 PM
Security Audit — agent-trust-hub — deno-frontend