icp-cli
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches CLI binaries and canister recipes from the official DFINITY GitHub repositories and the NPM registry. These sources are verified as official vendor resources.
- [COMMAND_EXECUTION]: Utilizes shell commands for project lifecycle management, including deployment and identity configuration. The operations described are standard and expected for a CLI-focused development skill.
- [DYNAMIC_EXECUTION]: Recommends the use of
child_process.execSyncwithinvite.config.jsto dynamically fetch canister status and network configuration. This pattern is a standard integration method for development tools and does not involve untrusted remote code. - [INDIRECT_PROMPT_INJECTION]: The skill processes project configuration files which act as ingestion points for the agent's context.
- Ingestion points:
icp.yaml,mops.toml(SKILL.md). - Boundary markers: None identified.
- Capability inventory: Includes execution of
icpandnpmCLI tools. - Sanitization: None specified for configuration file content.
- [CREDENTIALS_UNSAFE]: Provides instructions for identity management, specifically detailing the use of plaintext PEM files for local testing. The skill includes appropriate warnings, emphasizing that such storage should only be used for throwaway identities and not for those controlling mainnet assets.
Audit Metadata