canhelp
Warn
Audited by Socket on Sep 16, 2026
1 alert found:
SecuritySecurityscripts/resolve-canister-id.sh
MEDIUMSecurityMEDIUM
scripts/resolve-canister-id.sh
The script is a legitimate canister ID/name lookup utility, but it contains a command-construction flaw: untrusted input is embedded directly into Python source in the no-results path. This can permit Python code injection for crafted lookup values. The input should be passed as a separate `sys.argv` value or serialized safely rather than interpolated into the `-c` string. No clear malware behavior is present.
Confidence: 98%Severity: 70%
Audit Metadata