Skip to content
Back to skills

Deno

ASecurity

Build with Deno runtime avoiding permission gotchas, URL import traps, and Node.js migration pitfalls.

  • 17 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 6, 2026
developmenttypescriptgonodetestinggitapidatabasesecurity

Works with

  • api

Security analysis

A100/100

Pro scans all 5 files and shows the line behind each finding

Scanned September 6, 2026

npx -y skills add clawic/skills --skill deno --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Deno?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Deno
[![Security: A β€” Skills Directory](https://www.skillsdirectory.com/api/skills/clawic-deno/badge)](https://www.skillsdirectory.com/skills/clawic-deno)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: Deno
slug: deno
version: 1.0.0
description: Build with Deno runtime avoiding permission gotchas, URL import traps, and Node.js migration pitfalls.
homepage: https://clawic.com/skills/deno
metadata:
  clawdbot:
    emoji: πŸ¦•
    requires:
      bins:
      - deno
    os:
    - linux
    - darwin
    - win32
    displayName: Deno
---

## When to Use

User needs Deno expertise β€” secure TypeScript runtime with permissions model. Agent handles permission configuration, dependency management via URLs/npm, and migration from Node.js.

## Quick Reference

| Topic | File |
|-------|------|
| Permission system | `permissions.md` |
| Imports and dependencies | `imports.md` |
| Node.js migration | `node-compat.md` |

## Permission Traps

- `--allow-all` in development β€” then production crashes because you don't know what permissions you actually need
- `--allow-read` without path β€” grants access to entire filesystem, security hole
- `--allow-run` without list β€” subprocess can run anything, specify: `--allow-run=git,npm`
- `--allow-env` without list β€” leaks all env vars, specify: `--allow-env=API_KEY,DATABASE_URL`
- `--allow-net` without list β€” can connect anywhere, specify hosts: `--allow-net=api.example.com`
- Missing permission in CI β€” hangs waiting for prompt that never comes, add `--no-prompt`

## Import Traps

- Remote URLs in production β€” network failure = app won't start, vendor dependencies locally
- No lockfile by default β€” deps can change between runs, always use `deno.lock`
- `@^1.0.0` semver syntax doesn't exist β€” use exact URLs or import maps
- Import maps in wrong place β€” must be in `deno.json`, not separate file (Deno 2.x)
- HTTPS required β€” HTTP imports blocked by default, most CDNs work but self-hosted may not
- URL typo β€” no error until runtime when import fails

## TypeScript Traps

- `.ts` extension required in imports β€” model generates extensionless imports that fail
- `tsconfig.json` paths ignored β€” Deno uses import maps in `deno.json`, not tsconfig
- Type-only imports β€” must use `import type` or bundler may fail
- Decorators β€” experimental, different from tsc behavior
- `/// <reference>` β€” handled differently than tsc, may be ignored

## Deployment Traps

- `deno compile` includes runtime β€” binary is 50MB+ minimum
- `--cached-only` requires prior cache β€” fresh server needs `deno cache` first
- Deno Deploy limitations β€” no filesystem, no subprocess, no FFI
- Environment variables β€” different API: `Deno.env.get("VAR")` not `process.env.VAR`
- Signals β€” `Deno.addSignalListener` not `process.on("SIGTERM")`

## Testing Traps

- `Deno.test` different from Jest β€” no `describe`, different assertions
- Async test without await β€” test passes before promise resolves
- Resource leaks β€” tests fail if you don't close files/connections
- Permissions in tests β€” test may need different permissions than main code
- Snapshot testing β€” format differs from Jest snapshots

## npm Compatibility Traps

- `npm:` specifier β€” works for most packages but native addons fail
- `node:` specifier required β€” `import fs from 'fs'` fails, need `import fs from 'node:fs'`
- `node_modules` optional β€” enable with `"nodeModulesDir": true` in deno.json
- `package.json` scripts β€” not automatically supported, use deno.json tasks
- Peer dependencies β€” handled differently, may get wrong versions

## Runtime Differences

- `Deno.readTextFile` vs `fs.readFile` β€” different API, different error types
- `fetch` is global β€” no import needed, unlike Node 18-
- Top-level await β€” works everywhere, no wrapper needed
- Permissions at runtime β€” can request dynamically but user must approve

Files in this skill

  • SKILL.md3.6 KB
  • _meta.json160 B
  • imports.md2.6 KB
  • node-compat.md2.8 KB
  • permissions.md2.4 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…