state-invariant-detection

Warn

Audited by Socket on Mar 5, 2026

1 alert found:

Anomaly
AnomalyLOW
references/case-studies.md

The code contains intentional/instructional invariant-violation bugs: privileged functions and some operations update component state without updating corresponding aggregate state (totalSupply, totalStaked, totalRewards, kLast, totalFunds). These are serious correctness and financial-integrity issues that can be exploited to manipulate balances, rewards, AMM invariants, or apparent funds. However, there is no evidence of covert malicious actions (exfiltration, backdoor, obfuscation). The risk is primarily logical/financial (exploitable accounting bugs) rather than malware.

Confidence: 90%Severity: 60%
Audit Metadata
Analyzed At
Mar 5, 2026, 11:05 AM
Package URL
pkg:socket/skills-sh/quillai-network%2Fqs_skills%2Fstate-invariant-detection%2F@8f72771174e343855cc6d6c501c6fcce337a9c83