skills/okx/agent-skills/earn-hunter/Gen Agent Trust Hub

earn-hunter

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEPERSISTENCEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [PERSISTENCE]: The skill implements automated monitoring by installing a cron job (on Linux) or a LaunchAgent (on macOS) that executes a local shell script (scan.sh) at regular intervals. This behavior is transparently documented in the scheduler setup instructions.
  • [EXTERNAL_DOWNLOADS]: The skill installs the @okx_ai/okx-trade-cli package from the official npm registry during the installation phase. This is a vendor-owned package required for interacting with the OKX API.
  • [COMMAND_EXECUTION]: The skill manages and executes a bundled shell script (scripts/scan.sh) which uses jq for data processing and the okx CLI for fetching financial information. It also uses launchctl and crontab to manage its scheduled tasks.
  • [DATA_EXFILTRATION]: The skill sends financial opportunity data to external notification channels, including the Telegram Bot API and Lark Webhooks. These operations use well-known services and rely on environment variables for sensitive authentication tokens (TELEGRAM_BOT_TOKEN), which is a recommended security practice.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a potential attack surface as it ingests untrusted data from the OKX API (such as project names) and interpolates it into templates. While no malicious behavior was detected, there are no explicit boundary markers or 'ignore' instructions for the agent when processing this external content.
  • Ingestion points: Data enters via okx earn flash-earn projects, okx earn savings fixed-products, and okx earn savings rate-history commands called in scripts/scan.sh.
  • Boundary markers: Absent in the notification templates (templates/flash-earn.md, templates/fixed-earn.md, etc.).
  • Capability inventory: The skill uses exec (to run the scan script and CLI) and write (to manage state, config, and system persistence files).
  • Sanitization: The skill uses jq to parse and filter JSON data, which provides basic structural validation but does not include specific prompt-injection sanitization for natural language fields.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 02:12 PM
Security Audit — agent-trust-hub — earn-hunter