rivet-actors

Warn

Audited by Socket on Oct 3, 2026

4 alerts found:

Securityx3Anomaly
SecurityMEDIUM
examples/docs/actors-permissions/chat-room.ts

No clear malware behavior is present. The hardcoded, predictable authentication tokens are a significant security weakness if this actor is deployed with these values, especially because the admin token grants moderation permissions. Message rendering safety depends on downstream consumers.

Confidence: 99%Severity: 76%
SecurityMEDIUM
examples/docs/actors-permissions/caching-tokens.ts

The code has a serious authentication flaw: any non-empty token is accepted as the same hard-coded user. This can permit unauthorized connections and should not be used for real authentication without proper token verification. No evidence of malware or data exfiltration appears in this fragment.

Confidence: 99%Severity: 82%
SecurityMEDIUM
examples/docs/actors-permissions/create-conn-state.ts

No clear malware is present. The token validation is a significant authentication flaw: any nonempty token can connect with a fixed member identity and send messages. Message content is stored and broadcast without sanitization, so consumers should handle it safely.

Confidence: 99%Severity: 76%
AnomalyLOW
examples/docs/actors-request-handler/proxy.ts

This module is a generic request-forwarding gateway. The primary security concern is that user-controlled route parameters are used to (a) select an actor instance and (b) construct the destination URL via new URL(actorPath, "http://actor"), potentially allowing absolute URL overrides, and (c) proxy the entire incoming request (c.req.raw) into the forwarded Request. No validation/allowlisting is present in the shown code. While there is no clear evidence of intentional malware, the relay/target-injection pattern presents a credible SSRF/open-proxy and sensitive-header forwarding risk depending on deployment and rivetkit actor.fetch semantics.

Confidence: 62%Severity: 66%
Audit Metadata
Analyzed At
Oct 3, 2026, 06:59 PM
Package URL
pkg:socket/skills-sh/rivet-dev%2Fskills%2Frivet-actors%2F@f3c9e33a32c9323b91e67836a0d738d177a70a7318048650f390fd662f75bf73
Security Audit — socket — rivet-actors