canhelp

Warn

Audited by Socket on Sep 16, 2026

1 alert found:

Security
SecurityMEDIUM
scripts/resolve-canister-id.sh

The script is a legitimate canister ID/name lookup utility, but it contains a command-construction flaw: untrusted input is embedded directly into Python source in the no-results path. This can permit Python code injection for crafted lookup values. The input should be passed as a separate `sys.argv` value or serialized safely rather than interpolated into the `-c` string. No clear malware behavior is present.

Confidence: 98%Severity: 70%
Audit Metadata
Analyzed At
Sep 16, 2026, 02:50 PM
Package URL
pkg:socket/skills-sh/dfinity%2Ficskills%2Fcanhelp%2F@6dbc591b59b639f50bcde324cde3722982314080cad4201a4d5c8a645da36f55
Security Audit — socket — canhelp