helius-okx

Warn

Audited by Socket on Aug 2, 2026

1 alert found:

Anomaly
AnomalyLOW
references/integration-patterns.md

No direct evidence of intentional malware (e.g., backdoor, exfiltration, shell/persistence) is visible in the provided fragment. However, it demonstrates a high-impact automated trading flow where untrusted on-chain data determines which arguments are passed to a locally executed external CLI, whose untrusted JSON output is then used to gate trade execution. The execFileSync-based reliance on an external binary without shown integrity verification or strict validation materially increases supply-chain/host-security risk. This should be treated as a security alert for review of binary integrity controls, trust boundaries, and safety/confirmation mechanisms around swap execution.

Confidence: 45%Severity: 65%
Audit Metadata
Analyzed At
Aug 2, 2026, 03:59 PM
Package URL
pkg:socket/skills-sh/hosseinmirzapur%2Fopencode-skills%2Fhelius-okx%2F@b832a5179f1b047e5d52b97568f74bb284716514dedf38012b034b38dc630f9c
Security Audit — socket — helius-okx