deno-cli-tool

Warn

Audited by Socket on Mar 19, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill’s overall purpose is coherent for a Deno CLI guide, and its execution patterns are standard. The main concern is supply-chain trust: it mandates a personal JSR scope (`@totto2727/fp`) as the required Effect CLI source instead of the official Effect packages, creating an unnecessary publisher mismatch for a framework-oriented skill. No credential theft, exfiltration, or covert behavior is evident.

Confidence: 90%Severity: 52%
Audit Metadata
Analyzed At
Mar 19, 2026, 02:47 PM
Package URL
pkg:socket/skills-sh/totto2727-dotfiles%2Fagents%2Fdeno-cli-tool%2F@5c605f043343a085452259fae7d49cb793a04f82