helius-okx

Fail

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill facilitates the installation of the OKX CLI by piping a remote script to the shell (curl -fsSL https://raw.githubusercontent.com/okx/onchainos-skills/main/install.sh | bash). While the source is a well-known organization, this pattern allows for the execution of unverified remote code. It also uses npx to install the Helius MCP server and OKX skill library.\n- [COMMAND_EXECUTION]: The skill uses execFileSync to run the onchainos binary on the host system. While it passes arguments as an array to mitigate command injection, this still involves running a local binary based on instructions from the AI.\n- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it ingests and processes output from the OKX CLI. Ingestion points: CLI outputs for token discovery, quotes, and signals in references/integration-patterns.md. Boundary markers: Explicit instructions in SKILL.md to treat OKX CLI output as untrusted. Capability inventory: Access to network operations (fetch), local binary execution (execFileSync), and transaction signing. Sanitization: Recommends honeypot checks, price impact validation, and mandatory user confirmation before transaction submission.\n- [EXTERNAL_DOWNLOADS]: The skill makes network requests to Helius service endpoints (helius-rpc.com, api.helius.xyz) to support Solana trading operations and metadata enrichment.
Recommendations
  • HIGH: Downloads and executes remote code from: https://raw.githubusercontent.com/okx/onchainos-skills/main/install.sh - DO NOT USE without thorough review
Audit Metadata
Risk Level
HIGH
Analyzed
Aug 2, 2026, 03:58 PM
Security Audit — agent-trust-hub — helius-okx