aspire-cli

Warn

Audited by Socket on Mar 9, 2026

1 alert found:

Anomaly
AnomalyLOW
references/aspire-13.1-cli.md

The fragment is documentation only and does not itself contain executable code or active malware. The most significant security risk identified is the installation pattern curl ... | bash, which can lead to remote code execution if the remote script is compromised or tampered with. For secure use, ensure that installation scripts are fetched over TLS with integrity verification (signatures, hashes), and prefer safer installation approaches (e.g., downloading and verifying a script, or using package managers with verifiable signatures). The rest of the content describes configuration persistence and MCP setup, which are typical but should be reviewed for proper access controls and network policies in actual deployments.

Confidence: 65%Severity: 55%
Audit Metadata
Analyzed At
Mar 9, 2026, 11:18 PM
Package URL
pkg:socket/skills-sh/arisng%2Fgithub-copilot-fc%2Faspire-cli%2F@010d4350f4dc6caa18158fa5382a6c912b490fdf