surfpool

Warn

Audited by Socket on Sep 14, 2026

1 alert found:

Anomaly
AnomalyLOW
examples/cheatcodes/state-manipulation.ts

No direct malware behaviors (code execution, persistence, or exfiltration) are evident in this module. However, it is explicitly designed to call privileged surfnet_* cheatcode RPC methods that can mutate accounts/tokens and alter/restore network and simulated time state. The most significant risk is operational/supply-chain misuse: if SURFPOOL_RPC points to an untrusted or non-local endpoint (or is compromised), this client could enable destructive state manipulation. Treat as test-only tooling and restrict RPC endpoint/method access; avoid running with non-local HTTP endpoints in sensitive contexts.

Confidence: 70%Severity: 62%
Audit Metadata
Analyzed At
Sep 14, 2026, 10:08 PM
Package URL
pkg:socket/skills-sh/sendaifun%2Fskills%2Fsurfpool%2F@a80e2540d854cacf6bce051c0395baf9958906ca72168c0a244fba65f84649cc
Security Audit — socket — surfpool