okx-cex-portfolio
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEDATA_EXFILTRATIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill instructions direct the agent to execute
okx config show --json, which is identified as the authoritative source for API-key presence. This command accesses sensitive authentication material (API keys) stored in the local~/.okx/config.tomlfile and loads it into the agent's context for verification. - [EXTERNAL_DOWNLOADS]: The skill installs the
@okx_ai/okx-trade-clipackage from the npm registry during the installation phase. This is a vendor-owned resource corresponding to the skill author. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data retrieved from the OKX exchange API, which could potentially contain malicious instructions.
- Ingestion points: Data is ingested via commands such as
okx account balance-all,okx account positions, andokx account billswhich fetch account state and history from external servers. - Boundary markers: The skill does not define specific delimiters or instructions to ignore potential commands embedded within the retrieved account data or transaction ledgers.
- Capability inventory: The skill has the ability to execute shell commands (
okx) and perform sensitive write operations such as fund transfers (okx account transfer) and position mode changes. - Sanitization: There is no mention of sanitization or validation of the API response content before it is processed by the agent.
Audit Metadata