Is asksurf-ai/surf-skills safe?
Use with caution. asksurf-ai/surf-skills is not clearly unsafe, but the audit flagged risks to review before you install it. Oathe's behavioral security audit gave the surf-skills skill by asksurf-ai a trust score of 79/100 with 4 findings, none critical or high.
https://github.com/asksurf-ai/surf-skills
Is asksurf-ai/surf-skills safe to install?
The surf skill provides legitimate cryptocurrency data functionality via API calls, with transparent documentation and user permission requests for file modifications. However, sensitive credential files were accessed during the installation session, raising security concerns despite no evidence of exfiltration.
What security issues were found in asksurf-ai/surf-skills?
Category Scores
Findings (4)
MEDIUM Sensitive credential files accessed during session -35 ▶
Multiple sensitive credential files including .env, SSH private keys, AWS credentials, NPM config, Docker config, and Google Cloud credentials were accessed during the installation session. While no exfiltration occurred, this access pattern raises security concerns.
LOW Dependency on external CLI tool -20 ▶
The skill requires installation of an external Surf CLI tool from agents.asksurf.ai, which introduces additional attack surface and dependency on external infrastructure.
LOW Honeypot files accessed but not modified -15 ▶
Canary/honeypot files were accessed during the session, indicating potential reconnaissance activity, though no modifications or exfiltration occurred.
INFO Project file modification with permission -10 ▶
The skill requests permission to modify AGENTS.md or CLAUDE.md files to inject routing rules, but this is transparent and requires explicit user consent via AskUserQuestion.
Should I install asksurf-ai/surf-skills?
Oathe's verdict for asksurf-ai/surf-skills is CAUTION with a trust score of 79/100. Recommendation: Install with caution.