icp-cli
Warn
Audited by Socket on Sep 25, 2026
1 alert found:
AnomalyAnomalyreferences/dev-server.md
LOWAnomalyLOW
references/dev-server.md
The code implements a legitimate ICP/Vite development workflow and shows no clear malicious behavior. It contains a security weakness: ICP_ENVIRONMENT is interpolated into shell commands executed by execSync(), allowing command injection if that environment variable can be attacker-controlled. Validate it against an allowlist and preferably invoke the CLI without shell interpolation. The proxy target should also be restricted to trusted network endpoints. Risk is primarily local development-process command execution rather than package malware.
Confidence: 97%Severity: 62%
Audit Metadata