icp-cli

Warn

Audited by Socket on Sep 25, 2026

1 alert found:

Anomaly
AnomalyLOW
references/dev-server.md

The code implements a legitimate ICP/Vite development workflow and shows no clear malicious behavior. It contains a security weakness: ICP_ENVIRONMENT is interpolated into shell commands executed by execSync(), allowing command injection if that environment variable can be attacker-controlled. Validate it against an allowlist and preferably invoke the CLI without shell interpolation. The proxy target should also be restricted to trusted network endpoints. Risk is primarily local development-process command execution rather than package malware.

Confidence: 97%Severity: 62%
Audit Metadata
Analyzed At
Sep 25, 2026, 08:37 PM
Package URL
pkg:socket/skills-sh/dfinity%2Ficskills%2Ficp-cli%2F@a496bbd92b6b857cb3f2ce966e7d8daced34f124d2e4397ef507288585f59403
Security Audit — socket — icp-cli