earn-hunter
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEPERSISTENCEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [PERSISTENCE]: The skill implements automated monitoring by installing a cron job (on Linux) or a LaunchAgent (on macOS) that executes a local shell script (
scan.sh) at regular intervals. This behavior is transparently documented in the scheduler setup instructions. - [EXTERNAL_DOWNLOADS]: The skill installs the
@okx_ai/okx-trade-clipackage from the official npm registry during the installation phase. This is a vendor-owned package required for interacting with the OKX API. - [COMMAND_EXECUTION]: The skill manages and executes a bundled shell script (
scripts/scan.sh) which usesjqfor data processing and theokxCLI for fetching financial information. It also useslaunchctlandcrontabto manage its scheduled tasks. - [DATA_EXFILTRATION]: The skill sends financial opportunity data to external notification channels, including the Telegram Bot API and Lark Webhooks. These operations use well-known services and rely on environment variables for sensitive authentication tokens (TELEGRAM_BOT_TOKEN), which is a recommended security practice.
- [INDIRECT_PROMPT_INJECTION]: The skill has a potential attack surface as it ingests untrusted data from the OKX API (such as project names) and interpolates it into templates. While no malicious behavior was detected, there are no explicit boundary markers or 'ignore' instructions for the agent when processing this external content.
- Ingestion points: Data enters via
okx earn flash-earn projects,okx earn savings fixed-products, andokx earn savings rate-historycommands called inscripts/scan.sh. - Boundary markers: Absent in the notification templates (
templates/flash-earn.md,templates/fixed-earn.md, etc.). - Capability inventory: The skill uses
exec(to run the scan script and CLI) andwrite(to manage state, config, and system persistence files). - Sanitization: The skill uses
jqto parse and filter JSON data, which provides basic structural validation but does not include specific prompt-injection sanitization for natural language fields.
Audit Metadata