New:Microsoft Teams Notifications Are Now Available in Socket.Learn more →
Get Started

@orbit-tools/cli

Package Overview
Dependencies
Maintainers
1
Versions
31
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

@orbit-tools/cli

npm proxy for the Orbit CLI. Downloads the matching native binary from GitHub Releases on install and forwards all invocations.

latest
Source
npmnpm
Version
0.25.1
Version published
Weekly downloads
398
25.95%
Maintainers
1
Weekly downloads
 
Created
Source

@orbit-tools/cli

npm binary proxy for the Orbit CLI.

On install, downloads the matching prebuilt orbit binary from GitHub Releases, authenticates the signed orbit-checksums.txt with the package-pinned release trust set, verifies the archive SHA-256, and exposes it as the orbit command.

Usage

# Install globally
npm install -g @orbit-tools/cli
orbit --version
orbit init  # on Linux, also prepares and verifies Bubblewrap for this user

# One-shot via npx
npx -y @orbit-tools/cli mcp serve

All arguments are forwarded to the native orbit binary. The npm install lifecycle never requests administrator privileges. On Linux, orbit init is the explicit onboarding step that prepares the host when needed; a denied or unsupported host receives a precise readiness error.

Supported platforms

  • macOS arm64 / x64
  • Linux arm64 / x64

Windows is not currently published. Use WSL or build from source.

Environment variables

VariableEffect
ORBIT_BINARYPath to a local orbit binary; bypasses download and trusts that path as the binary source.
ORBIT_RELEASE_PUBLIC_KEY_FILEDeprecated in favor of ORBIT_RELEASE_TRUSTED_KEYS_FILE. Single-key override for the trusted checksum-signing public key; requires ORBIT_RELEASE_PUBLIC_KEY_FILE_ACKNOWLEDGE_TRUST_CHANGE=1, logs a deprecation notice when active.
ORBIT_RELEASE_PUBLIC_KEY_FILE_ACKNOWLEDGE_TRUST_CHANGE=1Required acknowledgement that ORBIT_RELEASE_PUBLIC_KEY_FILE replaces the release authenticity trust root.
ORBIT_RELEASE_TRUSTED_KEYS_FILEPreferred test/operations override for the full trusted signing-key set, including key IDs, not_after, and revoked_at; requires ORBIT_RELEASE_TRUSTED_KEYS_FILE_ACKNOWLEDGE_TRUST_CHANGE=1 and logs when active.
ORBIT_RELEASE_TRUSTED_KEYS_FILE_ACKNOWLEDGE_TRUST_CHANGE=1Required acknowledgement that ORBIT_RELEASE_TRUSTED_KEYS_FILE replaces the release authenticity trust root.
ORBIT_SKIP_DOWNLOAD=1Skip postinstall download (lazy install on first run still works).

License

MIT.

Keywords

orbit

FAQs

Package last updated on 01 Oct 2026

Related posts