surfpool

Warn

Audited by Socket on Aug 4, 2026

1 alert found:

Anomaly
AnomalyLOW
examples/cheatcodes/state-manipulation.ts

No direct malware behaviors (code execution, persistence, or exfiltration) are evident in this module. However, it is explicitly designed to call privileged surfnet_* cheatcode RPC methods that can mutate accounts/tokens and alter/restore network and simulated time state. The most significant risk is operational/supply-chain misuse: if SURFPOOL_RPC points to an untrusted or non-local endpoint (or is compromised), this client could enable destructive state manipulation. Treat as test-only tooling and restrict RPC endpoint/method access; avoid running with non-local HTTP endpoints in sensitive contexts.

Confidence: 70%Severity: 62%
Audit Metadata
Analyzed At
Aug 4, 2026, 12:35 AM
Package URL
pkg:socket/skills-sh/JustaName-id%2Fcryptoskills%2Fsurfpool%2F@0baaa39065c7b76e9a9b170ae53b8442d3e9f0518f786377f125dca37d410454
Security Audit — socket — surfpool