okx-cex-earn

Warn

Audited by Socket on Sep 24, 2026

2 alerts found:

Securityx2
SecurityMEDIUM
SKILL.md

BENIGN in purpose alignment and data flow: it appears to be an official OKX skill using the official local CLI and first-party auth flow, with no clear credential exfiltration or malicious install path. However, it is HIGH security risk because it grants an AI agent live financial transaction capability on a crypto exchange, includes transitive skill loading for re-auth, and instructs silent use of live mode.

Confidence: 91%Severity: 74%
SecurityMEDIUM
references/workflows.md

No malware or intentional supply-chain attack is evident. This is a readable operational guide for live OKX financial workflows. The principal concern is elevated financial-impact risk: commands can execute purchases, redemptions, transfers, and auto-earn changes, and the DCD workflow lacks a final explicit confirmation. Use least-privilege API permissions, require confirmation immediately before every write operation, and avoid unattended execution of live-account commands.

Confidence: 98%Severity: 72%
Audit Metadata
Analyzed At
Sep 24, 2026, 02:11 PM
Package URL
pkg:socket/skills-sh/okx%2Fagent-skills%2Fokx-cex-earn%2F@276715009672c34305e81bbc1802738863cff15a891f978289a847f2a7fdbae8
Security Audit — socket — okx-cex-earn