okx-v5-api

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructions direct the agent to clone a documentation repository from https://github.com/okx/ai-builder-openapi-md. This is the official repository for the vendor (OKX) and is used as the data source for the skill's lookup functionality.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from the documentation repository (JSON and Markdown files). This creates an attack surface for indirect prompt injection if the source repository were compromised. However, the risk is mitigated by the fact that the skill primarily performs read-only lookups and searches using local tools like rg (ripgrep) or jq, and it targets an official vendor repository.
  • Ingestion points: Files located at <docs_path>/sites.json, <docs_path>/index/*.md, <docs_path>/index.json, and various Markdown files within <docs_path>/docs/.
  • Boundary markers: None explicitly defined in the instructions.
  • Capability inventory: The skill performs file reads and regex searches. It does not contain capabilities for arbitrary code execution or network exfiltration based on the ingested data.
  • Sanitization: No specific sanitization or filtering of documentation content is described.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 02:10 PM
Security Audit — agent-trust-hub — okx-v5-api