cli-user

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external API responses (via the CLI) such as market prices and account balances, which are then used to formulate trade orders. \n
  • Ingestion points: Market ticker, instrument data, and account balance details retrieved in SKILL.md. \n
  • Boundary markers: The instructions specify using the --json flag to ensure data is ingested in a structured format. \n
  • Capability inventory: The skill can execute order placement and management commands like okx spot place and okx swap place. \n
  • Sanitization: No explicit sanitization or validation of the CLI output is defined in the instructions beyond standard JSON parsing by the agent. \n- [COMMAND_EXECUTION]: The skill's primary function is to drive the okx command-line utility (a vendor-owned resource) through shell commands to manage the user's trading account.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:02 AM
Security Audit — agent-trust-hub — cli-user