surfpool
Warn
Audited by Socket on Aug 4, 2026
1 alert found:
AnomalyAnomalyexamples/cheatcodes/state-manipulation.ts
LOWAnomalyLOW
examples/cheatcodes/state-manipulation.ts
No direct malware behaviors (code execution, persistence, or exfiltration) are evident in this module. However, it is explicitly designed to call privileged surfnet_* cheatcode RPC methods that can mutate accounts/tokens and alter/restore network and simulated time state. The most significant risk is operational/supply-chain misuse: if SURFPOOL_RPC points to an untrusted or non-local endpoint (or is compromised), this client could enable destructive state manipulation. Treat as test-only tooling and restrict RPC endpoint/method access; avoid running with non-local HTTP endpoints in sensitive contexts.
Confidence: 70%Severity: 62%
Audit Metadata