← Home

@phantom/cli

Phantom CLI — interact with your Phantom wallet from the terminal

1
Versions
License
Yes
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

joe-phantomfragostiphantom-security-bot

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
install-scripts install-script:postinstall AI (install-scripts): postinstall runs patch-package, a declared runtime dep used for patching; not arbitrary code execution. ai
semgrep semgrep:shady-links-raw-ip AI (semgrep): All raw-IP references are in test files using 127.0.0.1 (localhost) for callback server tests. ai
semgrep semgrep:base64-decode AI (semgrep): Base64 decoding in test files for OAuth Basic Auth header validation; no production payload hiding. ai
semgrep semgrep:env-spread AI (semgrep): env-spread is in a test file saving/restoring process.env around test cases; standard Jest pattern. ai
typosquat typosquat.levenshtein:joi AI (typosquat): @phantom/cli is a scoped CLI package; Levenshtein match to 'joi' is a false positive with no brand similarity. ai
phantom-deps phantom-dep:patch-package AI (phantom-deps): patch-package is declared in dependencies and used in postinstall; phantom-dep heuristic is a false positive here. ai

Versions (showing 1 of 1)

Version Deps Published
1.0.0 19 / 10

v1.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.