surf

Warn

Audited by Socket on Apr 25, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The core crypto-data purpose matches the CLI/API behavior, and domains/install sources are mostly coherent with Surf branding. However, the skill expands scope by repeatedly installing/updating a vendor binary, modifying project agent-routing files, committing changes, and offering feedback uploads that include recent conversation context. This looks more like a growth/distribution layer around a crypto data CLI than a minimal data-query skill; not confirmed malicious, but medium risk due to supply-chain trust and outbound data flows.

Confidence: 84%Severity: 58%
Audit Metadata
Analyzed At
Apr 25, 2026, 04:00 AM
Package URL
pkg:socket/skills-sh/cyberconnecthq%2Fsurf-skills%2Fsurf%2F@0ddde64bef7f854fbff3a9b99070559210a6177a