helius-okx
Warn
Audited by Snyk on Aug 2, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 1.00). The skill instructs the user to run a runtime install command that pipes a remote script to the shell (curl -fsSL https://raw.githubusercontent.com/okx/onchainos-skills/main/install.sh | bash), which fetches and executes remote code from https://raw.githubusercontent.com/okx/onchainos-skills/main/install.sh and is a required installation step.
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill explicitly describes and mandates on-chain trade execution: it documents DEX swap aggregation (OKX), transaction submission APIs (Helius "Sender"), patterns for swap/trading apps and trading bots, and strict "ALWAYS submit swap transactions via Helius Sender" rules (with fee and retry parameters). It also shows how to supply OKX API credentials. These are specific crypto transaction/execution tools (sending/signing/broadcasting trades), not generic browser or HTTP utilities — therefore it grants Direct Financial Execution Authority.
Issues (2)
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata