
Security News
/Company News
Securing the Financial Frontier: How Capital One Uses Socket for Open Source Security
Capital One is partnering with Socket to proactively secure its open source supply chain.
@orbit-tools/cli
Advanced tools
npm proxy for the Orbit CLI. Downloads the matching native binary from GitHub Releases on install and forwards all invocations.
npm binary proxy for the Orbit CLI.
On install, downloads the matching prebuilt orbit binary from
GitHub Releases, authenticates
the signed orbit-checksums.txt with the package-pinned release trust set,
verifies the archive SHA-256, and exposes it as the orbit command.
# Install globally
npm install -g @orbit-tools/cli
orbit --version
orbit init # on Linux, also prepares and verifies Bubblewrap for this user
# One-shot via npx
npx -y @orbit-tools/cli mcp serve
All arguments are forwarded to the native orbit binary.
The npm install lifecycle never requests administrator privileges. On Linux,
orbit init is the explicit onboarding step that prepares the host when
needed; a denied or unsupported host receives a precise readiness error.
Windows is not currently published. Use WSL or build from source.
| Variable | Effect |
|---|---|
ORBIT_BINARY | Path to a local orbit binary; bypasses download and trusts that path as the binary source. |
ORBIT_RELEASE_PUBLIC_KEY_FILE | Deprecated in favor of ORBIT_RELEASE_TRUSTED_KEYS_FILE. Single-key override for the trusted checksum-signing public key; requires ORBIT_RELEASE_PUBLIC_KEY_FILE_ACKNOWLEDGE_TRUST_CHANGE=1, logs a deprecation notice when active. |
ORBIT_RELEASE_PUBLIC_KEY_FILE_ACKNOWLEDGE_TRUST_CHANGE=1 | Required acknowledgement that ORBIT_RELEASE_PUBLIC_KEY_FILE replaces the release authenticity trust root. |
ORBIT_RELEASE_TRUSTED_KEYS_FILE | Preferred test/operations override for the full trusted signing-key set, including key IDs, not_after, and revoked_at; requires ORBIT_RELEASE_TRUSTED_KEYS_FILE_ACKNOWLEDGE_TRUST_CHANGE=1 and logs when active. |
ORBIT_RELEASE_TRUSTED_KEYS_FILE_ACKNOWLEDGE_TRUST_CHANGE=1 | Required acknowledgement that ORBIT_RELEASE_TRUSTED_KEYS_FILE replaces the release authenticity trust root. |
ORBIT_SKIP_DOWNLOAD=1 | Skip postinstall download (lazy install on first run still works). |
MIT.
FAQs
npm proxy for the Orbit CLI. Downloads the matching native binary from GitHub Releases on install and forwards all invocations.
The npm package @orbit-tools/cli receives a total of 250 weekly downloads. As such, @orbit-tools/cli popularity was classified as not popular.
We found that @orbit-tools/cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.