te-cli

Warn

Audited by Socket on Jul 21, 2026

1 alert found:

Anomaly
AnomalyLOW
references/config-cicd-env.md

No direct malicious behavior is evidenced in the provided instructions (they are operational CI/CD patterns). However, the workflow carries a significant supply-chain integrity risk: it installs and executes a `te` binary downloaded from a public CDN using an unpinned `latest` preview channel without shown checksum/signature verification. Because the resulting tool is then used with high-privilege service principal credentials to perform deploy/refresh/test actions against Fabric via XMLA/management APIs, a tampered artifact or compromised distribution would yield high-impact CI-to-cloud compromise. Mitigate by pinning to a specific version and verifying integrity (checksum/signature), restricting the service principal’s permissions to only the necessary workspaces/capacities/environments, and ensuring CI logs/test artifacts are guaranteed not to contain secret material.

Confidence: 62%Severity: 60%
Audit Metadata
Analyzed At
Jul 21, 2026, 10:02 AM
Package URL
pkg:socket/skills-sh/data-goblin%2Fpower-bi-agentic-development%2Fte-cli%2F@5ffdbb9c1a156f13c43a70856650677f3c99c2b24742c4d510ec2ce090abb491
Security Audit — socket — te-cli