surf

Warn

Audited by Socket on Aug 26, 2026

7 alerts found:

Securityx2Anomalyx5
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s capabilities broadly match its stated browser-automation purpose and it routes provider interactions through official web endpoints rather than a third-party gateway, so it is not confirmed malicious. However, it requires unusually high trust: unpacked extension + native host installation, broad authenticated browser control, OS-level desktop automation, arbitrary webpage processing, and optional execution of verification commands on downloaded/generated artifacts together make it a high-risk skill.

Confidence: 87%Severity: 78%
AnomalyLOW
vendor/surf-cli/native/host-helpers.cjs

The fragment is a browser automation command mapper and result formatter. It contains no evident malware, exfiltration logic, hardcoded secrets, obfuscation, or persistence. It does expose high-impact capabilities, including forwarding arbitrary JavaScript for execution, reading caller-selected files for batch actions, accessing cookies and network bodies, and uploading files. These are security risks if the tool interface is reachable by untrusted users or if downstream message handlers lack authorization and validation. The fragment alone does not establish malicious intent.

Confidence: 97%Severity: 58%
AnomalyLOW
cdp_client.py

The code is primarily a local CDP browser-automation controller, not clear malware. It contains powerful intentional browser capabilities and security weaknesses around unescaped JavaScript interpolation, unrestricted navigation/evaluation, arbitrary screenshot paths, and runtime pip installation. The supplied fragment is incomplete or malformed, limiting confidence in full-file assessment. No direct credential theft, persistence, reverse shell, cryptomining, destructive behavior, or suspicious external exfiltration is present.

Confidence: 94%Severity: 58%
AnomalyLOW
vendor/surf-cli/native/gemini-client.cjs

The fragment appears to be legitimate Gemini client and browser-integration code, with no clear malware or sabotage behavior. Significant security concerns are disabled TLS verification, unrestricted redirect handling with cookie forwarding, and caller-controlled filesystem paths. The hardcoded Basic credential should be verified against the intended Gemini upload protocol. Malware likelihood is low, while the implementation has moderate security risk if URLs, callbacks, or paths can be influenced by untrusted input.

Confidence: 95%Severity: 62%
AnomalyLOW
scripts/lib/anti_avoidance_gate.py

This is a readable anti-avoidance workflow utility. It does not show indicators of intentional malware or data theft. Its main security concern is deliberate but dangerous use of shell=True on a command taken from the gate JSON, combined with an unrestricted working directory. Untrusted gate files must not be processed, or blocker commands should be executed without a shell using an allowlisted executable and arguments. The Git subprocess calls use fixed arguments and appear comparatively safe.

Confidence: 98%Severity: 68%
AnomalyLOW
scripts/kde_spaces.py

The code appears to be a legitimate KDE desktop integration helper rather than malware. Its subprocess calls use fixed commands and do not provide an evident command-injection path. The main security concerns are an unauthenticated helper server, possible exposure of desktop/window metadata when bound beyond localhost, arbitrary helper URL forwarding that can leak tab or session data if configuration is altered, and unsafe handling of the predictable /tmp URL file. These are meaningful security weaknesses but do not by themselves indicate intentional malicious behavior.

Confidence: 97%Severity: 56%
SecurityMEDIUM
vendor/surf-cli/manifest.json

The manifest describes a highly privileged browser automation extension. Its broad all-URL access and permissions for cookies, history, downloads, debugger, scripting, and native messaging represent a significant security and privacy risk if implementation code or message validation is unsafe. No direct malicious behavior can be established from this manifest alone; review service-worker-loader.js, content/index.js, options code, native messaging configuration, and message authorization logic.

Confidence: 96%Severity: 78%
Audit Metadata
Analyzed At
Aug 26, 2026, 06:10 PM
Package URL
pkg:socket/skills-sh/grahama1970%2Fagent-skills%2Fsurf%2F@8403ebf066cc9681a13de96940b73b1c509601bda416cf24cfdf687105ce1d7b
Security Audit — socket — surf