okx-cex-portfolio

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEDATA_EXFILTRATIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill instructions direct the agent to execute okx config show --json, which is identified as the authoritative source for API-key presence. This command accesses sensitive authentication material (API keys) stored in the local ~/.okx/config.toml file and loads it into the agent's context for verification.
  • [EXTERNAL_DOWNLOADS]: The skill installs the @okx_ai/okx-trade-cli package from the npm registry during the installation phase. This is a vendor-owned resource corresponding to the skill author.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data retrieved from the OKX exchange API, which could potentially contain malicious instructions.
  • Ingestion points: Data is ingested via commands such as okx account balance-all, okx account positions, and okx account bills which fetch account state and history from external servers.
  • Boundary markers: The skill does not define specific delimiters or instructions to ignore potential commands embedded within the retrieved account data or transaction ledgers.
  • Capability inventory: The skill has the ability to execute shell commands (okx) and perform sensitive write operations such as fund transfers (okx account transfer) and position mode changes.
  • Sanitization: There is no mention of sanitization or validation of the API response content before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 02:11 PM
Security Audit — agent-trust-hub — okx-cex-portfolio