Official agent skill

Deno Runtime and Package Manager

by denoland in denoland/skills

Guides writing, running and configuring Deno 2.9+ projects: installing npm and JSR dependencies, permissions, config file precedence and the built-in fmt, lint, test and compile toolchain.

OfficialMITAuto-check passedDevelopment

Install Deno Runtime and Package Manager

skills CLI
$ npx skills add denoland/skills --skill deno -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install denoland/skills deno --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/denoland/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/deno .claude/skills/deno && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
deno
GitHub stars
100
Token cost
~2.7k tokens
SKILL.md length
973 words
Files
2 (incl. references)
Skills in repo
5
Repo updated
First seen
Licence
MIT

At a glance

Guides writing, running and configuring Deno 2.9+ projects: installing npm and JSR dependencies, permissions, config file precedence and the built-in fmt, lint, test and compile toolchain.

  • Scaffolding a new Deno project or adding dependencies to one
  • SKILL.md covers Deno works the way npm and bun…, Dependency management, Permissions and Configuration, plus 7 more sections
  • Calls deno, npm and pnpm; reaches deno.land
  • Debugging why an npm package's native addon isn't working after install

What it does

The skill treats Deno as compatible with the npm ecosystem rather than a separate one to port code into: deno install reads an existing package.json and writes a real node_modules, deno add express installs from npm by default, deno task runs scripts.build from package.json or tasks.build from deno.json (deno.json wins if both define it), and both prefixed and unprefixed Node built-ins resolve. It tells the agent not to ask users to rewrite imports or adopt JSR as a precondition, since the two real differences from Node are permissions and npm lifecycle scripts not running automatically.

For dependency management, deno ci is the CI-specific command: it requires deno.lock, deletes node_modules and installs strictly from the lockfile, failing if it is stale, with --prod skipping dev dependencies. Deno refuses to install a package version published less than a day ago by default, overridable with --min-dep-age, and postinstall-style lifecycle scripts need an explicit deno approve-scripts or --allow-scripts to run. A references/CLI.md file and a separate migrate-to-deno skill cover converting an existing project.

When your agent uses it

  • Scaffolding a new Deno project or adding dependencies to one
  • Debugging why an npm package's native addon isn't working after install
  • Deciding where a setting belongs across package.json, tsconfig.json and deno.json
  • Running Deno's built-in formatter, linter, tests or bundler

Example prompts

  • “Add express and the JSR path package to this Deno project.”
  • “Why isn't better-sqlite3 working after deno install? I think its postinstall didn't run.”
  • “Set up a deno.lock-based CI install step for this project.”

Requirements

  • Deno 2.9 or newer

What it can do on your machine

Read from SKILL.md and the folder at commit d5f6ace. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • deno
    • npm
    • pnpm
    • yarn

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • deno.land

    Also links to:

    • docs.deno.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Deno Runtime and Package Manager loads about 2.7k tokens when it runs, and up to ~5.4k if it reads all its reference files. Until then it costs about 107 tokens; SKILL.md has 973 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~107
When it runs · the whole SKILL.md, loaded when a task matches
~2.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~5.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from denoland/skills at commit d5f6ace, republished under its MIT licence (© denoland). 973 words, ~2,720 tokens.

Download SKILL.mdSave it as .claude/skills/deno/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
deno
description
Use when writing, running, configuring, reviewing, or debugging code in a Deno project, or when scaffolding a new one. Covers dependency management with deno install and deno add, package.json and node_modules support, npm and JSR packages, permissions, where configuration belongs across package.json, tsconfig.json and deno.json, workspaces, the built-in toolchain (fmt, lint, test, check, bench, compile), and publishing.
license
MIT
metadata.author
denoland
metadata.version
1.0

Deno

A JavaScript and TypeScript runtime with a package manager, formatter, linter, test runner, type checker, and bundler in one binary. Runs TypeScript directly.

Needs Deno 2.9+. Check with deno --version, update with deno upgrade.

Deno works the way npm and bun do

Deno is not a separate ecosystem to port code into:

  • deno install reads an existing package.json and writes a real node_modules.
  • deno add express installs from npm. Unprefixed names default to npm.
  • deno task build runs scripts.build from package.json or tasks.build from deno.json. If both define it, deno.json wins.
  • Node built-ins work prefixed or not: node:fs and fs both resolve.
  • deno main.js runs a file. deno run is optional.
  • Deno reads tsconfig.json.

Don't tell users to rewrite imports, adopt JSR, or restructure as a precondition. The two real differences are permissions and npm lifecycle scripts not running by default.

Single-file scripts need no build step and no tsconfig.json. Applications and framework projects keep their normal setup.

To convert an existing project, see the migrate-to-deno skill.

Dependency management

bash
deno install                  # install everything declared
deno add express              # from npm (unprefixed = npm)
deno add jsr:@std/path        # from JSR
deno add -D vitest            # dev dependency (package.json only)
deno remove express
deno outdated                 # list outdated deps
deno update                   # alias for `deno outdated --update`
deno update --latest          # ignore existing semver ranges
deno list                     # declared deps + resolved versions (npm ls)
deno why express              # why a package is in the tree
deno audit                    # vulnerability audit
deno ci                       # clean reproducible install for CI
dx cowsay hello               # run a package binary without installing (npx)

deno ci is the CI command, not deno install: it requires deno.lock, deletes node_modules, installs strictly from the lockfile, and fails if the lockfile is stale. --prod skips devDependencies.

dx is npx / bunx / pnpm dlx, and an alias for deno x. It runs with the sandbox disabled, so treat it with the same care as npx.

Deno won't install a version published less than a day ago, limiting the window for a compromised release. Override with --min-dep-age, which takes minutes (120), an ISO-8601 duration (P7D), a cutoff date, or 0 to disable:

bash
deno add --min-dep-age=0 npm:some-package

Lifecycle scripts (postinstall) don't run by default — a common surprise when a native addon looks broken after install. Approve once per project:

bash
deno approve-scripts                              # interactive picker
deno install --allow-scripts=npm:better-sqlite3
Where configuration goes
FileHolds
package.jsondependencies, scripts
tsconfig.jsonTypeScript compiler options
deno.jsonDeno config: fmt, lint, tasks, workspaces

Put dependencies in package.json — every other tool reads it, and Deno resolves it natively. Use deno.json for dependencies only when there is no package.json: a standalone script, or a JSR package. Likewise prefer tsconfig.json over compilerOptions in deno.json, so tsc and editors see the same settings.

Commit deno.lock. Deno seeds it from an existing package-lock.json, yarn.lock, bun.lock, or pnpm lockfile, preserving pins.

node_modules layout

Deno uses pnpm's isolated layout: real files in node_modules/.deno/, exposed by symlinks, so a package can't import what it never declared. For a tool that needs npm's flat hoisted tree:

json
{ "nodeModulesLinker": "hoisted" }

nodeModulesDir applies only to projects without a package.json, so it is rarely the right knob.

Permissions

Deno grants no filesystem, network, environment, or subprocess access unless asked.

bash
deno run --allow-net=api.example.com --allow-read=./data main.ts
deno run -A main.ts          # allow everything
FlagShortGrants
--allow-read[=paths]-Rfilesystem read
--allow-write[=paths]-Wfilesystem write
--allow-net[=hosts]-Nnetwork
--allow-env[=names]-Eenvironment variables
--allow-sys[=apis]-SOS information
--allow-import[=hosts]-Iimports from remote hosts
--allow-run[=bins]—subprocesses
--allow-ffi[=paths]—native libraries (unstable)
--allow-all-Aeverything

-S is --allow-sys, not --allow-run. Every flag takes an allowlist — --allow-net=example.com:443 beats bare --allow-net. Matching --deny-* flags always win.

On Requires net access to "...", add that specific permission. -A is fine for trusted first-party code and during migration, but a poor default to commit in a task.

Configuration

deno.json (or .jsonc) is auto-discovered from the current directory upward.

json
{
  "tasks": {
    "dev": "deno watch -A main.ts",
    "start": "deno run -A main.ts"
  },
  "fmt": { "exclude": ["build/"] },
  "lint": { "rules": { "exclude": ["no-explicit-any"] } },
  "exclude": ["build/", "dist/"]
}

Top-level exclude applies to every subcommand; per-tool exclude narrows it.

deno.json also accepts imports, an import map pointing bare specifiers at real ones. That is how a project without package.json declares dependencies, and how a JSR package declares its own alongside name, version, exports.

Show full SKILL.md (411 more words)Show less
Workspaces

npm, Yarn, and Bun workspaces work out of the box — Deno reads package.json "workspaces" directly. pnpm is the exception: pnpm-workspace.yaml is migrated into deno.json on first run, which must then be re-run.

json
{ "workspace": ["./packages/core", "./packages/cli"] }

Members are explicit or single-level globs ("packages/*"); ** and negation are unsupported. Run a task across members with deno task --filter '*' build.

Packages: npm and JSR

Prefer npm — it is where the ecosystem is, and deno add express is the normal case. Reach for JSR for the standard library (@std/*), or to publish TypeScript that consumers get types for without a build step. Mixing is fine.

bash
deno add jsr:@std/path npm:express
deno doc jsr:@std/path        # read a package's API from the terminal

Deno once used full URL imports (https://deno.land/x/...). They still run but aren't recommended; to modernize, deno add the package and import the bare specifier.

Built-in tooling

bash
deno fmt              # format (--check for CI)
deno lint             # lint (--fix, --rules)
deno test             # tests (--watch, --parallel, --coverage=dir)
deno check main.ts    # type-check without running
deno bench            # benchmarks
deno coverage         # coverage report from --coverage output
deno compile main.ts  # single-file executable (--target cross-compiles)
deno doc mod.ts       # docs (--html for a site)
deno info main.ts     # module graph and cache info

These cover prettier, eslint, jest/vitest, tsc, and pkg/nexe with no config or dependencies — but they are not drop-in replacements. Parity is incomplete, so moving an established project is real work. There is no need to migrate: keep prettier, eslint, and vitest, and use Deno as runtime and package manager. Prefer the built-in tools for new projects.

Suppress with // deno-lint-ignore <rule>, // deno-lint-ignore-file, // deno-fmt-ignore, // deno-fmt-ignore-file. In Markdown, <!-- deno-fmt-ignore --> before a code block protects illustrative snippets that aren't valid standalone code.

Running code

bash
deno main.ts                 # deno run is optional
deno watch main.ts           # reload on change (replaces nodemon)
deno task dev                # task from package.json or deno.json
deno repl
deno eval "console.log(1)"

deno watch hot-replaces modules, restarting if that fails; it aliases deno run --watch-hmr.

An HTTP server needs no dependencies:

ts
Deno.serve((_req) => new Response("Hello"));

Starting a new project

Scaffold rather than hand-writing the files:

bash
deno init my-project          # script + test + deno.json
deno init --empty my-project  # just main.ts and deno.json
deno init --lib my-lib        # library laid out for JSR
deno create vite my-app       # scaffold from a package initializer

deno create is npm create / yarn create and covers that ecosystem (deno create astro, etc). Unprefixed names are npm; --jsr selects JSR.

Publishing

To npm the regular flow still works — npm publish, or deno pack to build the tarball first. deno publish targets JSR only, from a deno.json with name, version, and exports:

bash
deno publish --dry-run
deno publish

Provenance attestation is automatic on GitHub Actions. deno bump-version patch bumps the version, across every member at a workspace root.

Guide: https://docs.deno.com/runtime/reference/cli/publish/

Reviewing Deno code

  • -A committed in a task where a scoped grant would work.
  • deno.lock uncommitted, or CI running deno install instead of deno ci.
  • Inline jsr:/npm: specifiers in a project with a package.json — use deno add so the version lives in one place. Fine in standalone scripts.
  • A specifier with no version constraint.
  • Dependencies or compiler options in deno.json when package.json or tsconfig.json exists.
  • Missing deno fmt --check, deno lint, deno check in CI.

Further reading

  • https://docs.deno.com — runtime documentation
  • https://docs.deno.com/api/ — Deno.* API reference
  • references/CLI.md — fuller subcommand and flag reference
  • deno <subcommand> --help — authoritative and version-accurate; check it before guessing at a flag.

© denoland, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/deno of denoland/skills.

  • SKILL.md
  • references/CLI.md

Open the folder on GitHubat commit d5f6ace

Compare with similar skills

Deno Runtime and Package Manager next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Deno Runtime and Package Manager compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Deno Runtime and Package Manager this skilldenoland/skills100—~2.7kAutomated safety check: PassMIT
Create Saleor Packagesaleor/apps162—~608Automated safety check: PassCustom licence
npm Packagejwynia/agent-skills166—~2.1kAutomated safety check: PassNone
Npx CLIjwynia/agent-skills166—~2.4kAutomated safety check: PassNone
npm Supply Chain Securitybodadotsh/npm-security-best-practices859—~1kAutomated safety check: WarnMIT
Pre Commitwellwelwel/poku1.2k—~728Automated safety check: PassMIT

Similar skills

  • Scaffold a new shared package in the saleor-apps monorepo under ./packages/.

    162 GitHub stars~608 tokensUpdated yesterday
    DevelopmentAuto-check passed
  • npm Package

    jwynia/agent-skills

    Build and publish npm packages using Bun as the primary toolchain with npm-compatible output.

    166 GitHub stars~2.1k tokensUpdated 7 mo ago
    DevelopmentAuto-check passed
  • Npx CLI

    jwynia/agent-skills

    Build and publish npx-executable CLI tools using Bun as the primary toolchain with npm-compatible output.

    166 GitHub stars~2.4k tokensUpdated 7 mo ago
    DevelopmentAuto-check passed
  • npm Supply Chain Security

    bodadotsh/npm-security-best-practices

    Applies safer package manager defaults and dependency vetting to JavaScript and TypeScript projects to reduce supply-chain attack risk.

    859 GitHub stars~1k tokensUpdated 8 days ago
    SecurityAuto-check: warnings
  • Pre Commit

    wellwelwel/poku

    Run the mandatory pre-commit checks for the poku repository before staging a commit.

    1.2k GitHub stars~728 tokensUpdated 3 mo ago
    Testing & QAAuto-check passed
  • Installs, updates or migrates the vendored anti-slop Oxlint plugin in a repository, keeping local rule changes and the plugin's license and provenance files.

    5.3k GitHub starsUsed in 1 repo~2.2k tokens
    DevelopmentAuto-check passed

More from denoland/skills

  • Official

    Chooses between running regular npm frontend frameworks under Deno and building with Fresh, Deno's island-architecture framework, with Fresh 2.x guidance.

    100 GitHub stars~783 tokensUpdated 2 mo ago
    Auto-check passed
  • Deno Deploy

    denoland/skills

    Official

    Guides deploying Deno apps with the deno deploy CLI, including pre-flight checks, environment variables, Deno KV, custom domains and the --tunnel flag for local development.

    100 GitHub stars~5.5k tokensUpdated 2 mo ago
    Auto-check: notes
  • Deno Sandbox SDK

    denoland/skills

    Official

    Runs untrusted or AI-generated code in isolated Deno Sandbox microVMs using the @deno/sandbox SDK, with lifecycle, process and streaming guidance.

    100 GitHub stars~2.7k tokensUpdated 2 mo ago
    Auto-check passed
  • Migrate to Deno

    denoland/skills

    Official

    Moves a Node.js, npm, Yarn, pnpm or Bun project to Deno in reversible steps, starting with Deno as the package manager and changing no code unless needed.

    100 GitHub stars~2.2k tokensUpdated 2 mo ago
    Auto-check: warnings

Categories

Questions about Deno Runtime and Package Manager

What does Deno Runtime and Package Manager do?

Guides writing, running and configuring Deno 2.9+ projects: installing npm and JSR dependencies, permissions, config file precedence and the built-in fmt, lint, test and compile toolchain. json wins if both define it), and both prefixed and unprefixed Node built-ins resolve. It tells the agent not to ask users to rewrite imports or adopt JSR as a precondition, since the two real differences from Node are permissions and npm lifecycle scripts not running automatically.

When should I use Deno Runtime and Package Manager?

Deno Runtime and Package Manager fits situations like: scaffolding a new Deno project or adding dependencies to one; debugging why an npm package's native addon isn't working after install; deciding where a setting belongs across package.json, tsconfig.json and deno.json; running Deno's built-in formatter, linter, tests or bundler.

How do I install Deno Runtime and Package Manager in Claude Code?

Run `npx skills add denoland/skills --skill deno -a claude-code`. Or copy the skill folder (skills/deno in denoland/skills) into .claude/skills/deno in your project. Claude Code loads it when a task matches its description.

How do I install Deno Runtime and Package Manager in Codex?

Run `npx skills add denoland/skills --skill deno -a codex`. Or copy the skill folder (skills/deno in denoland/skills) into .agents/skills/deno in your project. Codex loads it when a task matches its description.

Can I use Deno Runtime and Package Manager in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add denoland/skills --skill deno -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/deno, .gemini/skills/deno, .github/skills/deno and .opencode/skills/deno in your project.

What does Deno Runtime and Package Manager need to run?

Going by SKILL.md and its folder, Deno Runtime and Package Manager needs the command-line tools its instructions call (deno, npm, pnpm and yarn). Our summary lists: Deno 2.9 or newer.

Does Deno Runtime and Package Manager access the network?

SKILL.md names 2 domains. In commands or code: deno.land; the agent is likely to contact it when it follows the instructions. As links in the text: docs.deno.com. This is read from the text; nothing was executed.

Is Deno Runtime and Package Manager safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Deno Runtime and Package Manager use?

Deno Runtime and Package Manager is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Deno Runtime and Package Manager use?

About 2.7k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.7k tokens, read only when the agent opens those files.

What are the alternatives to Deno Runtime and Package Manager?

Skills that share tags, products or a category with Deno Runtime and Package Manager: Create Saleor Package (saleor/apps, 162 stars), npm Package (jwynia/agent-skills, 166 stars), Npx CLI (jwynia/agent-skills, 166 stars) and npm Supply Chain Security (bodadotsh/npm-security-best-practices, 859 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Deno Runtime and Package Manager?

denoland (a GitHub organization, an official publisher) maintains it in denoland/skills, which has 100 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on July 29, 2026.

Source: denoland/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.