icp-appgen

Fail

Audited by Socket on Feb 16, 2026

1 alert found:

Obfuscated File
Obfuscated FileHIGH
assets/workflows/build.yml

The workflow is functionally benign for building an ICP application but contains a high-risk supply-chain pattern: executing a remote installer script fetched at runtime without integrity or authenticity verification (curl | sh). This permits arbitrary code execution on the CI runner if the remote script or transport is compromised and could lead to secret exfiltration or environment compromise. Recommend replacing the piped installer with a pinned, signed release or a vetted action, verifying checksums/signatures, restricting secret access for the job that runs installers, and adding caching or hermetic tool provisioning to eliminate runtime fetches.

Confidence: 98%
Audit Metadata
Analyzed At
Feb 16, 2026, 01:34 PM
Package URL
pkg:socket/skills-sh/codecustard%2Ficp-appgen-skill%2Ficp-appgen%2F@41ad24c9aea9cbc852ee7a2cb5bb92f79aa1712b