
Product
Introducing Socket Scanning for VS Code Marketplace Extensions
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.
@orbit-tools/cli
Advanced tools
npm proxy for the Orbit CLI. Downloads the matching native binary from GitHub Releases on install and forwards all invocations.
npm binary proxy for the Orbit CLI.
On install, downloads the matching prebuilt orbit binary from
GitHub Releases, authenticates
the signed orbit-checksums.txt with the package-pinned release trust set,
verifies the archive SHA-256, and exposes it as the orbit command.
# Install globally
npm install -g @orbit-tools/cli
orbit --version
# One-shot via npx
npx -y @orbit-tools/cli mcp serve
All arguments are forwarded to the native orbit binary.
Windows is not currently published. Use WSL or build from source.
| Variable | Effect |
|---|---|
ORBIT_BINARY | Path to a local orbit binary; bypasses download and trusts that path as the binary source. |
ORBIT_RELEASE_PUBLIC_KEY_FILE | Deprecated in favor of ORBIT_RELEASE_TRUSTED_KEYS_FILE. Single-key override for the trusted checksum-signing public key; requires ORBIT_RELEASE_PUBLIC_KEY_FILE_ACKNOWLEDGE_TRUST_CHANGE=1, logs a deprecation notice when active. |
ORBIT_RELEASE_PUBLIC_KEY_FILE_ACKNOWLEDGE_TRUST_CHANGE=1 | Required acknowledgement that ORBIT_RELEASE_PUBLIC_KEY_FILE replaces the release authenticity trust root. |
ORBIT_RELEASE_TRUSTED_KEYS_FILE | Preferred test/operations override for the full trusted signing-key set, including key IDs, not_after, and revoked_at; requires ORBIT_RELEASE_TRUSTED_KEYS_FILE_ACKNOWLEDGE_TRUST_CHANGE=1 and logs when active. |
ORBIT_RELEASE_TRUSTED_KEYS_FILE_ACKNOWLEDGE_TRUST_CHANGE=1 | Required acknowledgement that ORBIT_RELEASE_TRUSTED_KEYS_FILE replaces the release authenticity trust root. |
ORBIT_SKIP_DOWNLOAD=1 | Skip postinstall download (lazy install on first run still works). |
MIT.
FAQs
npm proxy for the Orbit CLI. Downloads the matching native binary from GitHub Releases on install and forwards all invocations.
The npm package @orbit-tools/cli receives a total of 529 weekly downloads. As such, @orbit-tools/cli popularity was classified as not popular.
We found that @orbit-tools/cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.

Security News
/Company News
Capital One is partnering with Socket to proactively secure its open source supply chain.